<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.techradar.com/feeds/tag/cybercrime" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from TechRadar in Cybercrime ]]></title>
                <link>https://www.techradar.com/computing/computing-security/cybercrime</link>
        <description><![CDATA[ All the latest cybercrime content from the TechRadar team ]]></description>
                                    <lastBuildDate>Mon, 27 Jul 2026 00:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-2-2-million-cars-could-be-at-risk-of-hijacking-via-bluetooth</link>
                                                                            <description>
                            <![CDATA[ Researchers find dealer-installed KARR and SWDS security systems are open to a Bluetooth-based hack which can remotely unlock doors and stop a vehicle from starting. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">G7JrH4KatQ5aFECzCy6c4f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jul 2026 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand over a concealed car door handle]]></media:description>                                                            <media:text><![CDATA[A hand over a concealed car door handle]]></media:text>
                                <media:title type="plain"><![CDATA[A hand over a concealed car door handle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California</strong></li><li><strong>The vulnerability is due to dealer-installed security systems</strong></li><li><strong>Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key</strong></li></ul><p>A vulnerability has been found in KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.</p><p>Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be elsewhere in the US, and even as far afield as Japan.</p><p>Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped.</p><h2 id="how-bluetooth-controls-these-cars">How Bluetooth controls these cars</h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/xS_4dNRGkoA" allowfullscreen></iframe></div></div><p>The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver-side window, with the anti-theft device mounted under the dashboard. </p><p>Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isn’t already running. </p><p>The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.</p><p>Changing the secure key isn’t an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesn’t pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn, and headlamps.</p><p>“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully released in August). “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”</p><h2 id="the-patch-is-in">The patch is in</h2><p>Jerry Yu, also co-author, wrote “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”</p><p>KARR has <a href="https://www.theregister.com/security/2026/07/23/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth/5277315" target="_blank">told</a> media outlets that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a <a href="https://www.karrsecurity.com/karr-security-firmware-update-instructions" target="_blank">firmware update</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake FBI social media scams are on the rise — here's what to look out for ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/fake-fbi-social-media-scams-are-on-the-rise-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Victims reporting crimes to the FBI are actually being caught and revictimized, leading to further financial losses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3zSRMcDm3LticiguF3F3Nh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Scammers are pretending to offer FBI support to victims</strong></li><li><strong>Victims are becoming double-victims after falling for this trap</strong></li><li><strong>FBI's IC3 warns never to pay for support – support will come from law enforcement</strong></li></ul><p>Scammers are increasingly impersonating FBI personnel and the FBI's Internet Crime Complaint Center (IC3) to defraud people who have already lost money to cybercrime, ultimately leading to them being exploited twice in quick succession by capitalizing on their weaknesses.</p><p>Attackers pose as support for recovering lost money and assisting with IC3 complaints, but the real objective is to defraud victims out of even more money or sensitive information.</p><p>But savvy victims should be able to identify these scams relatively easy, because despite a rising volume, the attack vector remains highly suspicious.</p><h2 id="victims-are-being-hit-twice-via-fake-fbi-scams">Victims are being hit twice via fake FBI scams</h2><p>Rather than targeting the FBI's website, scammers send direct messages to victims or attract them via posts or ads on social media. "Some individuals received an email or a phone call, while others were approached via social media or forums," the FBI <a href="https://www.ic3.gov/PSA/2025/PSA250418" target="_blank">explained</a>.</p><p>In the post, the FBI warns that attackers meet victims where they are, such as on Facebook, then quickly move them away to other, more secure channels like Telegram and connect them with other associates. </p><p>"The IC3 will not ask for payment to recover lost funds," the bureau warned, noting that victims should be weary of being contacted after reporting an attack. "If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers."</p><p>Victims who have either been attacked once, or attacked for a second time while trying to report the first attack, should report it via www.ic3.gov. The DOJ Elder Justice Hotline (1-833-FRAUD-11) also offers support for citizens aged 60+.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US sanctions on rogue VPN accidentally break Telegram's short links worldwide ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/us-sanctions-on-rogue-vpn-accidentally-break-telegrams-short-links-worldwide</link>
                                                                            <description>
                            <![CDATA[ Telegram’s t.me domain was swept up in a global outage following US Treasury sanctions against First VPN services, causing millions of web links to break worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4P42CJuXVG9W8YZrgU7CEJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:43:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Milman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Jaque Silva/NurPhoto via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[The Telegram logo appears on the screen of a smartphone that rests on top of a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zcpy2igVUaP9YqtCiCVXaE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US Treasury sanctioned First VPN Service for aiding ransomware gangs</strong></li><li><strong>Complying with the sanctions, the .ME registry wrongly suspended Telegram's entire t.me domain</strong></li><li><strong>The domain was restored roughly 19 hours later after Telegram CEO Pavel Durov flagged the issue online</strong></li></ul><p>If you clicked a Telegram link on Monday and stared at a blank screen, you weren't alone. Every shortlink starting with 't.me' suddenly vanished from the global internet, breaking group invites, profile shares, and channel links for roughly a billion users worldwide.</p><p>But the outage wasn't caused by a technical glitch or a targeted cyberattack. Instead, it was the unintended collateral damage of a US government crackdown on a cybercriminal proxy network.</p><p>On July 13, the US Treasury Department's Office of Foreign Assets Control (OFAC) <a href="https://www.techradar.com/vpn/vpn-privacy-security/first-vpn-administrators-sanctioned-by-us-treasury-over-ransomware-attacks">sanctioned the administrators of a rogue proxy network</a> called First VPN Service (1VPNS), aiming to cut off infrastructure used by ransomware operators. </p><p>While anyone shopping for the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> expects privacy, First VPN actively courted cybercriminals with promises of total anonymity, leading <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">European law enforcement to pull the plug on the service</a> earlier in May.</p><p>As part of the new sanctions, the US Treasury published a list of web addresses associated with the VPN. Buried in that list was a link to First VPN's public Telegram support channel: t.me/FirstVPNService.</p><h2 id="a-sledgehammer-to-crack-a-nut">A sledgehammer to crack a nut</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qp6PFkub49CUBhgFaHwjeQ" name="First VPN" alt="This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, "This service has been seized"" src="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)</span></figcaption></figure><p>Because top-level domains operate under strict international compliance rules, domain registrars must act quickly when sanctioned entities use their infrastructure.</p><p>Identity Digital, the company managing the technical backend for the .me domain, <a href="https://meduza.io/en/news/2026/07/14/u-s-treasury-sanctions-on-a-vpn-service-knocked-out-telegram-s-short-link-domain-worldwide" target="_blank" rel="nofollow">confirmed that the t.me domain had been blocked</a> at the request of OFAC. </p><p>However, because a domain registry cannot selectively disable a specific webpage or channel path — like a single Telegram group — the Montenegro-based registry Domain.Me applied a "serverHold" status to Telegram's entire t.me domain.</p><p>This sweeping action effectively erased the domain from the global <a href="https://www.techradar.com/vpn/what-is-dns">Domain Name System (DNS)</a>. The core Telegram app continued to function, and the older telegram.me domain remained active, but the shortlinks the messaging platform is built upon went entirely dark.</p><h2 id="the-swift-resolution">The swift resolution</h2><p>The sudden shutdown prompted immediate action from Telegram's leadership. </p><p>Unaware of the backend domain hold, Telegram CEO Pavel Durov <a href="https://x.com/durov/status/2076836338117046660" target="_blank" rel="nofollow">took to X</a> to publicly ask the registrar for an explanation: "Hey @domainME, t.me links stopped working. Can you look into it?"</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">Hey @domainME, https://t.co/9z6UC2o37U links stopped working. Can you look into it? 🙏<a href="https://twitter.com/cantworkitout/status/2076836338117046660">July 14, 2026</a></p></blockquote><div class="see-more__filter"></div></div><p>Once the sanctions issue was identified, Telegram scrubbed the offending channels from its platform. The registry operator subsequently verified the compliance and brought the domain back online.</p><p>"On 13 July, 1VPNS was included as a sanctioned entity by the US Department of the Treasury. A Telegram channel using the t.me domain was among 1VPNS identified infrastructure. Accordingly, the t.me domain was suspended," domain.Me confirmed in a <a href="https://x.com/domainme/status/2077077395777994942" target="_blank" rel="nofollow">statement<u> </u></a>following the outage.</p><p>The registrar clarified that normal service resumed roughly a day later, after Telegram provided confirmation that it had removed its links and affiliations with 1VPNS. "We appreciate Telegram's prompt cooperation in resolving this matter," domain.Me added.</p><p>While the outage is now resolved, the incident highlights a glaring vulnerability in the modern web, where a single URL swept up in a government sanctions list can inadvertently silence an essential communication channel for millions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ First VPN administrators sanctioned by US Treasury over ransomware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/first-vpn-administrators-sanctioned-by-us-treasury-over-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ Following a massive Europol takedown in May, the US Treasury has officially sanctioned the administrators behind First VPN, a service favored by ransomware groups to hide their tracks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xcqXWhLyXc3yCpMeVRFUCX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 09:39:52 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Jul 2026 11:05:33 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Milman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Fred TANNEAU / AFP via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:description>                                                            <media:text><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:text>
                                <media:title type="plain"><![CDATA[This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, &quot;This service has been seized&quot;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The US Treasury has sanctioned First VPN's administrator for aiding ransomware attacks on American infrastructure</strong></li><li><strong>Another suspect was targeted for selling "cryptors" that cloak malware from security systems</strong></li><li><strong>The move follows a May 2026 takedown by European law enforcement and the FBI that seized the VPN's infrastructure</strong></li></ul><p>The United States government has officially issued sanctions against the operators of a notorious virtual private network (VPN), escalating a global crackdown on digital infrastructure used to facilitate ransomware attacks.</p><p>On Monday (July 13), the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated First VPN Service (also known as 1VPNS) and its Ukrainian administrator, Dmytro Rashevskyi, for abetting cybercriminals. The service, which has operated since 2014, was heavily favored by ransomware gangs targeting American hospitals, municipalities, and businesses.</p><p>While the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services are designed to protect everyday consumer privacy, rogue networks like First VPN provided malicious actors with the tools to "hide the origins of their attacks, deploy malware, and manage exfiltrated data," according to a <a href="https://home.treasury.gov/news/press-releases/sb0559" target="_blank" rel="nofollow">Treasury Department press release</a>.</p><p>As part of the same action, the Treasury also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national accused of selling "cryptors" to ransomware operators. </p><p>While Silayev is not directly affiliated with First VPN, his inclusion in the sanctions package highlights a broader strategy of targeting the entire cybercriminal supply chain. Cryptors are tools specifically built to disguise ransomware as harmless files, preventing security systems from detecting or deactivating the malware.</p><h2 id="a-haven-for-cybercriminals">A haven for cybercriminals</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:940px;"><p class="vanilla-image-block" style="padding-top:57.98%;"><img id="U3nMoaJ3iNrFx8Qwkwmw7d" name="Shutterstock_1050436496.jpg" alt="Code Skull" src="https://cdn.mos.cms.futurecdn.net/U3nMoaJ3iNrFx8Qwkwmw7d.jpg" mos="" align="middle" fullscreen="" width="940" height="545" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The US Treasury's latest move is an update to an ongoing international operation against First VPN. </p><p>In a massive <a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">May 2026 takedown</a>, a coordinated effort led by European law enforcement agencies and the FBI successfully seized the service's website and server infrastructure.</p><p>Prior to the takedown, Rashevskyi aggressively marketed First VPN on dark web forums. To lure cybercriminals, he promised total anonymity and boasted that the network "does not keep logs of users' identities or activities, and that it refuses to cooperate with law enforcement investigations into illegal activity originating from the servers it rents to customers".</p><p>According to the US Treasury, Rashevskyi went to great lengths to keep the operation running. He utilized false identities, such as "Maksim Sorin" and "Roman Chabanenko," to "buy infrastructure from companies that might otherwise refuse to do business with him because of complaints of abuse from internet service providers about illegal activity originating from 1VPNS servers".</p><h2 id="disrupting-the-cybercriminal-ecosystem">Disrupting the cybercriminal ecosystem</h2><p>This latest wave of sanctions was coordinated alongside the United Kingdom's Foreign, Commonwealth & Development Office (FCDO) and carries severe consequences for the designated individuals.</p><p>Under the new sanctions, all property and interests belonging to Rashevskyi and Silayev within the US are blocked, and US citizens are strictly prohibited from engaging in any transactions with them. Beyond the immediate financial freeze, OFAC sanctions serve as a massive reputational blow designed to choke off future revenue streams.</p><p>By focusing on the service providers and tool suppliers who facilitate these attacks, rather than just the ransomware operators themselves, authorities are aiming to maximize their impact and disrupt multiple gangs at once.</p><p>"Under President Trump's leadership, Treasury is using every available tool to disrupt the cybercriminal ecosystem and protect the American people," said Gene Lange, who is performing the duties of the Under Secretary for Terrorism and Financial Intelligence. "We will continue targeting the actors who enable ransomware attacks against Americans and our critical infrastructure".</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Baby Boomers beat Gen Z in password hygiene, but both generations still don’t stick to the best practices — and many people are still using decades-old passwords that they made as kids ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/baby-boomers-beat-gen-z-in-password-hygiene-but-both-generations-still-dont-stick-to-the-best-practices-and-many-people-are-still-using-decades-old-passwords-that-they-made-as-kids</link>
                                                                            <description>
                            <![CDATA[ Baby Boomers are the most likely to frequently change passwords, but often rely on unsecure methods of storage. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9x7M8jUKqaYHh5NJXopDLJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 07 Jul 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World Password Day]]></media:description>                                                            <media:text><![CDATA[World Password Day]]></media:text>
                                <media:title type="plain"><![CDATA[World Password Day]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uUiBRJLfaEQ4McLrFtB7wd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordPass study claims older generations are more likely to change passwords than younger generations</strong></li><li><strong>But younger users are more in tune with password storage services, preferring to use password managers over memory and writing them down</strong></li><li><strong>All generations are failing to adhere to the best practices when it comes to password hygiene</strong></li></ul><p>Many people may believe Gen Z are the best when it comes to adopting new tech, but a new study by <a href="https://nordpass.com/blog/password-decline-research/" target="_blank">NordPass</a> polling 7,861 respondents between the ages of 18-74 suggests that they might be the worst generation for password hygiene.</p><p>It’s not uncommon for people to pick a particular word or phrase as a password and alternate special characters, numbers, and capital letters to keep it ‘unique’, but this practice is weakened when the same central password is used for years—or even decades.</p><p>In fact, Gen Z has been found to be the generation least likely to change a password, while Baby Boomers are the most security-conscious, actively updating their passwords much more frequently.</p><h2 id="baby-boomers-value-security">Baby Boomers value security</h2><p>When breaking down the stats, NordPass found just 54% of respondents had changed their longest-standing password in the last 12 months. Those aged 18-24 were the least likely to say they had updated their password within the last year, while those in older brackets, particularly between 55-to-64, were the most likely to update their passwords.</p><p>But there is a further trend to be examined. While those in the older age brackets are more likely to update their passwords, they rely on memory or physically writing down their passwords for storage. And those in the younger, more tech-savvy age brackets were more likely to rely on browser-based password storage or third-party password managers.</p><p>Writing down passwords or relying on memory often leads to the reuse of passwords to keep them memorable and easy to type, increasing the risk that personal accounts could be breached in the event of a cyberattack. While the average number of password has dropped from 168 in 2024 to 120 in 2026, this still leaves the average person with a significant number of possibly reused passwords that could leak, potentially compromising every account they are used on.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1062px;"><p class="vanilla-image-block" style="padding-top:62.52%;"><img id="tyRwAMqY2pue95yY3VEbzR" name="infographics-password-decline" alt="A graph displaying the average password storage statistics with respondents from Australia, Canada, the UK, the US, France, Germany, Italy, and Spain, showing more people store passwords in a browser." src="https://cdn.mos.cms.futurecdn.net/tyRwAMqY2pue95yY3VEbzR.jpg" mos="" align="middle" fullscreen="" width="1062" height="664" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: NordPass)</span></figcaption></figure><p>Opting for the convenience of a browser-based password manager also introduces additional risk, as these password vaults often aren’t subjected to the same security protocols as third-party <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager apps</a>. </p><p>In fact, another recent NordPass study highlighted that <a href="https://www.techradar.com/pro/security/password-reuse-only-sharpens-this-problem-browser-based-password-storage-isnt-as-safe-as-you-think-these-top-tips-from-the-experts-show-how-it-should-be-done" target="_blank">browser-based passwords are at a significantly higher chance of being leaked or stolen</a> thanks to malware, browser compromise, or physical access to the computer.</p><p>This is especially true for those using a browser-based password manager alongside a third-party app, because if the browser is compromised there is little you can do to protect your stored passwords.</p><p>“I’m fairly certain most internet users know they should immediately change a password that has been compromised,” said Karolis Arbaciauskas, head of product at cybersecurity company NordPass.</p><p>“So when people say they haven’t changed a password in years, either the password hasn’t been exposed, or they simply don’t know it has. I hate to be a bearer of bad news, but the second scenario is far more likely. Without tools to notify them when credentials appear in leaks or breaches, many users have passwords aging in the background while the risk grows.”</p><h2 id="how-to-keep-your-passwords-as-secure-as-possible">How to keep your passwords as secure as possible</h2><p>There are many ways to <a href="https://www.techradar.com/pro/security/coming-up-with-a-new-password-doesnt-have-to-be-hard-im-a-password-expert-and-these-are-my-5-top-tips-for-crafting-the-perfect-password">create a secure password</a>. These are my expert recommendations for maximizing your password security:</p><ul><li>Your password should be at least 15 characters long</li><li>Rather than relying on a memorable phrase or key date, use a string of random words such as the NIST example of ‘cassette-lava-baby’</li><li>Add in some random capitalization, numbers, and special characters, but avoid replacing certain letters with predictable special characters (such as ‘@’ for ‘a’, ‘$’ for ‘s’, and so on)</li><li>If you are forced to regularly change a password as many people are forced to do in the workplace, always use a new, unique password, rather than relying on ‘Summer12345’ followed by ‘Autumn12345’</li><li>Wherever possible, use an <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">authenticator app</a>. This can range from an app on your phone that you use to approve a login or a physical security key that you keep on your person. Many authenticators use phishing resistant passkeys that authenticate your login attempts by using your facial scan or a fingerprint</li><li>Use a password manager to store your passwords securely. They also add the benefit of being able to autofill your credentials for you</li><li>Use a credential exposure checking service such as <a href="https://haveibeenpwned.com/" target="_blank">Have I Been Pwned</a> to securely check if your email address or passwords have shown up in any dark web databases</li><li>Delete any online accounts you no longer use. If the service suffers a data breach, it could leak your username and password combination</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malaysia is cracking down on VPN misuse, but your VPN stays perfectly legal ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/malaysia-is-cracking-down-on-vpn-misuse-but-your-vpn-stays-perfectly-legal</link>
                                                                            <description>
                            <![CDATA[ Malaysia says it will act against VPNs used to facilitate crimes such as online scams and child exploitation, but ministers confirm that ordinary, lawful VPN use remains legal. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6XApHaMiryYgTkHuULA4yJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HqPrzKWLAnMS44eCiRPwW-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jul 2026 16:40:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/HqPrzKWLAnMS44eCiRPwW-1280-80.png">
                                                            <media:credit><![CDATA[Future + Sergio Amiti via Getty Images+ Photo by Jaap Arriens/NurPhoto via Getty Images  ]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[Malaysian flag blowing in the wind on the left, VPN icon on smartphone on the right]]></media:text>
                                <media:title type="plain"><![CDATA[Malaysian flag blowing in the wind on the left, VPN icon on smartphone on the right]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HqPrzKWLAnMS44eCiRPwW-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Malaysia beefs up action against VPN used to facilitate crimes</strong></li><li><strong>Misuse includes bypassing the new under-16 social media ban</strong></li><li><strong>Officials have stressed that owning or using a VPN is not an offence</strong></li></ul><p>Malaysia is set to take action if VPN are used to facilitate criminal activities or help residents bypass the new social media age limit. </p><p>According to <a href="https://www.thestar.com.my/news/nation/2026/07/02/govt-steps-up-measures-against-vpn-abuse-third-party-identities-in-online-child-protection" target="_blank" rel="nofollow">local reports</a>, Deputy Home Minister Datuk Seri Dr Shamsul Anuar Nasarah said the government is working closely with the Malaysian Communications and Multimedia Commission (MCMC) to counter VPNs and borrowed identities that are being used to slip past newly enforced social media age limits.</p><p>For the many people who reach for the <a href="https://www.techradar.com/vpn/best-vpn">best VPN</a> services to protect their browsing, encrypt their traffic, or simply keep their data out of advertisers' hands, the reassuring takeaway is that the tool itself is not the target. What the authorities want to reach is the small share of activity where a VPN is used as a shield for something illegal.</p><h2 id="what-malaysia-actually-announced">What Malaysia actually announced</h2><p>The comments came during a question-and-answer session on cybercrime and age verification. Shamsul Anuar explained that police would draw on public complaints and their own investigations to identify cases where VPNs or identity-masking tools are being abused, and that such misuse could be treated as an added element of an offence.</p><p>He was clear that the crackdown is aimed at conduct, not software. The minister framed the effort as part of Malaysia's wider push to protect children online, pointing to a sharp rise in offences.</p><p>This sits on top of <a href="https://www.nbcnews.com/world/asia/malaysia-enforces-ban-social-media-accounts-children-younger-16-rcna347823" target="_blank" rel="nofollow">Malaysia's under-16 social media ban</a>, which took effect on 1 June 2026 under the Online Safety Act 2025. Large platforms including Facebook, Instagram, TikTok, and YouTube must now verify users' ages and block under-16s from registering, with non-compliance carrying penalties reported at up to RM10 million. </p><p>VPNs enter the picture because they are an obvious way to make it look as though a user is somewhere the rules do not apply. Age verification laws elsewhere, <a href="https://www.techradar.com/vpn/vpn-privacy-security/under-16s-social-media-ban-lands-in-australia">such as Australia</a> and <a href="https://www.techradar.com/news/live/uk-social-media-ban-june-2026">the UK</a>, have repeatedly triggered spikes in VPN sign-ups, with many often being adults looking to protect the sensitive documents these systems ask them to hand over.</p><h2 id="what-it-means-for-everyday-vpn-users">What it means for everyday VPN users</h2><p>For most people, this is not a reason to stop using a VPN, and it is not a ban in disguise. </p><p>Digital rights groups, however, have been sharply critical of the age-verification model underpinning the ban. </p><p><a href="https://www.article19.org/resources/malaysia-mandatory-age-verification-undermines-privacy-and-free-expression/" target="_blank" rel="nofollow">ARTICLE 19</a>, alongside local partners, has argued the measure was rushed, is disproportionate, and risks normalising surveillance while exposing people's identity documents and biometric data to misuse. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 81 million login attempts hit Microsoft 365 accounts as hackers try password-spraying to force entry using stolen credentials and OAuth to bypass authentication ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/81-million-login-attempts-hit-microsoft-365-accounts-as-hackers-try-password-spraying-to-force-entry-using-stolen-credentials-and-oauth-to-bypass-authentication</link>
                                                                            <description>
                            <![CDATA[ The attack abused misconfigured conditional access policies to bypass multi-factor authentication protections. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d8vfHgQqzay2L4VV6dTngh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365]]></media:description>                                                            <media:text><![CDATA[Microsoft 365]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9dJG7jH8XprNiB4jnuuD2M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A password-spraying attack successfully breached Microsoft 365 accounts</strong></li><li><strong>The hackers abused improperly configured conditional access policies to bypass MFA</strong></li><li><strong>Many organizations targeted had no MFA implemented</strong></li></ul><p>Hackers have used previously leaked credentials to target Microsoft 365 accounts in a password-spraying attack that resulted in over 81 million login attempts during a two-week period.</p><p>The attackers then abused the improperly implemented Conditional Access policies within the Resource Owner Password Credentials (ROPC) OAuth mechanism using Azure command-line interface (CLI), allowing the hackers to bypass authentication altogether when a matching username and password was discovered.</p><p>Cybersecurity company <a href="https://www.huntress.com/blog/lshiy-password-spray-attack" target="_blank">Huntress</a> observed the attack campaign as it targeted customers and noted that 78 Microsoft accounts across 64 organizations were compromised between June 12 and 26 2026.</p><h2 id="hackers-access-365-accounts-without-authentication">Hackers access 365 accounts without authentication</h2><p>The success of the attack ultimately came down to how well organizations had implemented Conditional Access policies relating to multi-factor authentication. </p><p>“Many of the compromised businesses had implemented multi-factor authentication (MFA) via a Conditional Access Policy (CAP), but the MFA was not configured to cover this specific flow that attackers used,” Huntress explained, referring to the exploitation of ROPC.</p><p>“ROPC is considered problematic for several reasons, but one of those reasons is that it doesn't offer support for modern auth flows like MFA or SSO. That means, as we saw in this campaign, ROPC sends the password straight to the /token endpoint with no interactive MFA prompt.”</p><p>Several of the organizations that were breached did not enforce an MFA policy at all, with others only applying MFA for specific user groups such as administrators. In other cases, a login attempt only required MFA when the traffic was coming from an untrusted location, meaning that MFA was not enforced if the connection was coming from a trusted IP address. Additionally, some organizations had only enforced MFA in report-only mode, meaning that the MFA policies were never actually applied.</p><p>In order to protect against attacks of this kind of attack, Huntress recommended the following mitigations:</p><ul><li>Organizations should implement MFA for All Users, All Cloud Apps, and All Client App types</li><li>The Azure CLI application should be restricted from use by non-admin users</li><li>Response to the attack should be made on credential validity, rather than spray volume</li></ul><p>Via <a href="https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘100% of Hide My Email addresses were exploitable’: Apple’s security feature can be duped into supplying the real contact info — and the bug has remained unpatched for over a year ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/100-percent-of-hide-my-email-addresses-were-exploitable-apples-security-feature-can-be-duped-into-supplying-the-real-contact-info-and-the-bug-has-remained-unpatched-for-over-a-year</link>
                                                                            <description>
                            <![CDATA[ The bug was reported to Apple over a year ago, but still nothing has been done. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8zAuVdPwPxYpCY6BAjr9eN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 13:57:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple / 9to5Mac]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:description>                                                            <media:text><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot showing Hide My Email in the Mail app]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NhJKejfFerSum2SW4TXEkX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple Hide My Email can reveal a user's authentic email address</strong></li><li><strong>The bug puts users at risk of identification, experts warned</strong></li><li><strong>It has been unpatched for over a year</strong></li></ul><p>A bug in Apple’s ‘Hide My Email’ feature allows for those with knowledge of the vulnerability to identify the real email address hidden behind the anonymous email address.</p><p>The bug was discovered by EasyOptOuts co-founder, Tyler Murphy, who shared the exploit with <a href="https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/" target="_blank"><em>404 Media</em></a> after notifying Apple multiple times that the feature could be actively exploited.</p><p>“We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer,” Murphy said.</p><h2 id="hide-my-email-can-be-actively-exploited">Hide My Email can be actively exploited</h2><p>As the bug still hasn’t been patched, the details of how the exploit works have not been shared. </p><p>Apple’s Hide My Email feature was designed to anonymize email addresses, helping to prevent a user’s real email address from being leaked in a data breach, or to prevent a user’s email address from being linked to them personally in a way that could reveal their identity.</p><p>There lies the crux of the issue. By being able to identify the real email address by exploiting the bug, a malicious actor could uncover the real identity of the anonymized email.</p><p>“Free, publicly accessible people-search sites make it easy to link an email address to other personal details, so people relying on Hide My Email for safety may be at risk,” Murphy said. “We don't know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable.”</p><p>Users concerned about being identified via people-search sites can use a <a href="https://www.techradar.com/pro/best-data-removal-services-of-year" target="_blank">data removal service</a> to have their data scrubbed from these sites, but the process can take a few days.</p><p>The issue was first reported to Apply by Murphy in June 2025, with Apple replying a month later that it was looking into the cause of the issue. Earlier this year, in March, Apple said that it had “addressed the reported issue in a recent system change,” but Murphy found that the bug could still be exploited.</p><p>Again, Murphy notified Apple, who replied in May 2026, stating, “We are still investigating this issue. To avoid placing our customers at risk, we would appreciate you not disclosing this information until our investigation is complete. We appreciate your assistance in helping us to maintain and improve the security of our products."</p><p>Later in the same month, Apply said a fix was “expected in the coming weeks."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nearly 400 illegal World Cup 2026 streaming sites taken offline by US DOJ ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/nearly-400-illegal-world-cup-2026-streaming-sites-taken-offline-by-us-doj</link>
                                                                            <description>
                            <![CDATA[ Operation Offsides was a coordinated takedown of sites illegal streaming World Cup games. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bb9zwqtckkZobw2ECG6Aq6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2TTaVZdSSeLQizvYPKXnck-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 13:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Streaming]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2TTaVZdSSeLQizvYPKXnck-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Michael Regan - FIFA]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FIFA World Cup 2026 in Washington DC]]></media:description>                                                            <media:text><![CDATA[FIFA World Cup 2026 in Washington DC]]></media:text>
                                <media:title type="plain"><![CDATA[FIFA World Cup 2026 in Washington DC]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2TTaVZdSSeLQizvYPKXnck-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US DOJ has seized nearly 400 domains</strong></li><li><strong>The sites were being used to illegally stream World Cup games</strong></li><li><strong>Users of the sites were exposed to malware, data theft, and other threats</strong></li></ul><p>Almost 400 domains have been seized as part of Operation Offsides - a coordinated global effort to take down sites illegally streaming the FIFA World Cup 2026.</p><p>The sites were seized by the US Justice Department's Criminal Division for violating copyright and intellectual property law.</p><p>The takedowns were coordinated by members of the International Computer Hacking and Intellectual Property (ICHIP) network.</p><h2 id="us-and-friends-enforce-the-offside-rule">US and friends enforce the offside rule</h2><p>Many of the seized domains now display a banner explaining that the website was seized as part of Operation Offsides. “This action was taken to protect consumers and enforce intellectual property rights worldwide,” the banner states.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:628px;"><p class="vanilla-image-block" style="padding-top:60.83%;"><img id="wSkc22iLD5oCmHtsdaH9MZ" name="seizure_banner_fifa_world_cup" alt="A screenshot of the banner uploaded to domains seized by the US DOJ that were illegal streaming 2026 FIFA World Cup games." src="https://cdn.mos.cms.futurecdn.net/wSkc22iLD5oCmHtsdaH9MZ.webp" mos="" align="middle" fullscreen="" width="628" height="382" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: U.S. Justice Department)</span></figcaption></figure><p>Back in May 2026, the FBI warned that thousands of domains were being registered ahead of the World Cup, with most set up with the intention to scam fans looking for cheap tickets, access to streaming services, and those looking for discounted merchandise. It appears that Operation Offside was focused on disrupting streaming sites in particular, rather than taking down the wider scam networks associated with these domains.</p><p>“We have seized hundreds of domains, used to illegally stream World Cup matches for profit, to disrupt the international networks that profit from the global popularity of the World Cup,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division.</p><p>“This operation illustrates the Department’s respect for intellectual property rights and the responsibility of the United States as a host nation to protect the FIFA World Cup from criminals. The Criminal Division will continue to disrupt and, where appropriate, seek to prosecute these sites and the subjects responsible for this criminal activity.”</p><p>In many cases, the networks of fake domains offering cheap or free access to streaming services are run by cybercriminals deliberately operating at a loss in order to attract users to their services. In return for accessing the streaming site, the domain will use the user’s local network as an exit node for the cybercriminal network, obscuring their traffic and making it appear legitimate.</p><p>Unfortunately for the user, who may think they have just found <a href="https://www.techradar.com/how-to-watch/football/world-cup-2026-free-anywhere">free access to every World Cup game</a>, their network and IP address could be used to distribute malware, cybercriminal communications, and illegal content such as stolen data and exploitative materials - including child sex abuse material.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI warns of Russian Intelligence phishing campaign abusing Signal support services to target VIPs and high-value government and military targets — this is how to secure your account ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/fbi-warns-of-russian-intelligence-phishing-campaign-abusing-signal-support-services-to-target-vips-and-high-value-government-and-military-targets-this-is-how-to-secure-your-account</link>
                                                                            <description>
                            <![CDATA[ Russian Intelligence are trying to hijack Signal accounts by tricking users into sending their Backup Recovery Keys ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NFHSVuh7G9qYjTamC5fMmJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zjaJ25xrgFNLKEHr8bjVcY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 18:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Email &amp; Messaging]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zjaJ25xrgFNLKEHr8bjVcY-1280-80.jpg">
                                                            <media:credit><![CDATA[Michele Ursi / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WhatsApp and Signal app icons]]></media:description>                                                            <media:text><![CDATA[WhatsApp and Signal app icons]]></media:text>
                                <media:title type="plain"><![CDATA[WhatsApp and Signal app icons]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zjaJ25xrgFNLKEHr8bjVcY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian Intelligence are targeting Signal accounts of officials based in Ukraine</strong></li><li><strong>They pose as Signal support services and ask users to submit their Backup Recovery Keys</strong></li><li><strong>Using these keys, the hackers can hijack the users account and any other accounts created using the same mobile phone number</strong></li></ul><p>The FBI has warned Russian Intelligence Services are posing as commercial messaging application support services in order to steal Backup Recovery Keys belonging to targets of high value in the military and government of the US, Europe, and Ukraine.</p><p>In a <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank">joint warning</a> alongside the CISA and the Security Service of Ukraine (SSU), the FBI outlined the new phishing campaign which seeks to access messaging accounts in order to perform intelligence gathering of secret information.</p><p>Specifically, the FBI provided sample phishing lures targeting users of the Signal messaging app. If the hackers successfully lure a victim into sharing their Backup Recovery Key, they can access the account's message history, private and group messages, and fully take over the victim's account.</p><h2 id="russian-intelligence-pose-as-signal-support-services">Russian Intelligence pose as Signal support services</h2><p>In the FBI warning, the phishing techniques are further detailed. The Russian Federal Security Service (FSB) are targeting government officials, military personnel, political figures, journalists, and key officials from the US and Europe located in Ukraine.</p><p>The attackers send emails that appear to be automated messages from Signal, asking users to turn on their message backup using their Backup Recovery Key. Victims are provided with false instructions that instead send the Backup Recovery Key to the attacker, who can then use the key to take over the victim’s account.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:777px;"><p class="vanilla-image-block" style="padding-top:108.62%;"><img id="JoZ4UqwN8LL25f5u4bEqvH" name="Screenshot 2026-06-29 131941" alt="Example phishing messages used by Russian Intelligence, supplied by the FBI" src="https://cdn.mos.cms.futurecdn.net/JoZ4UqwN8LL25f5u4bEqvH.png" mos="" align="middle" fullscreen="" width="777" height="844" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Example phishing messages used by Russian Intelligence to obtain Backup Recovery Keys </span><span class="credit" itemprop="copyrightHolder">(Image credit: FBI)</span></figcaption></figure><p>In order to establish urgency and trust that the message is legitimate, the attackers posed the phishing message as a protection against recent hacking attempts from “Iran and post-Soviet countries.” In another sample message, the attacker's message says that the victim’s account data “is at risk of permanent loss due to a sync issue.”</p><p>If a victim shares their unique Backup Recovery Key, it allows the attacker to hijack their current Signal account alongside any subsequent accounts made with the same phone number.</p><p>For users who may fear their Backup Recovery Key has been compromised, users are instructed to use Signal settings to create a new Backup Recovery Key. This new key will invalidate all previous Backup Recovery Keys and prevent account takeover if the previous key was leaked.</p><p>In order to avoid falling victim to phishing messages, there are several ways to stay safe:</p><ul><li>Support services will generally only communicate with users via an official company email address. Always carefully check communications from the legitimate email address.</li><li>Customer support will never request that you supply your Backup Recovery Key via the application</li><li>You will never be asked to verify or restore your account via an automated customer support message</li></ul><p>In order to further protect your Signal account, or other accounts, against phishing, users should consider the following:</p><ul><li>Use a passkey wherever possible. This will use your device’s built in biometric verification methods to authenticate your login.</li><li>Use phishing resistant multi-factor authentication where possible</li><li>Always double check messages and emails are legitimate, and are using an official company email</li><li>Never supply your Backup Recovery Keys unless you are actively attempting to regain access to your account via a legitimate service</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 14 million login credentials leaked from six ISPs in major data breach — here’s what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/over-14-million-login-credentials-leaked-from-six-isps-in-major-data-breach-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ The credentials were exposed via an attack on third-party software. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q3LqdS6SNsXmNzrsX9V2tX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 17:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Email &amp; Messaging]]></category>
                                                    <category><![CDATA[Software &amp; Services]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Tens of millions of credentials may have been leaked following an attack on one of Japan's largest ISPs</strong></li><li><strong>The attack leveraged a vulnerability in a third-party software used by KDDI</strong></li><li><strong>Five other ISPs were also affected in the attack</strong></li></ul><p>A data breach that has potentially exposed the email and password combinations for over 14 million customers across six internet service providers (ISPs) has been disclosed by Japanese telecoms provider KDDI Corporation.</p><p>According to the company, hackers exploited a vulnerability in a third-party software to access the database of credentials. KDDI said that it immediately blocked the hackers' access after discovering the intrusion on June 17, 2026.</p><p>“Although technical defensive measures have already been implemented for the system, there remains a possibility that customers' email addresses and passwords were obtained by unauthorized third parties as a result of the incident,” the company said in a <a href="https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-71_4593/kddi_nr_s-71_4593_pdf_01.pdf" target="_blank" rel="nofollow">statement</a>.</p><h2 id="millions-of-credentials-exposed">Millions of credentials exposed</h2><p>Unfortunately, the breach was not confined to just KDDI. The email services of five other ISPs were also affected by the breach:</p><ul><li>STNet, Inc.</li><li>JCOM Co., Ltd.</li><li>Chubu Telecommunications C., Inc.</li><li>NIFTY Corporation</li><li>BIGLOBE Inc.</li></ul><p>KDDI is yet to finish a formal investigation into the attack, but said that the hacker may have gained access to the emails addresses and passwords for 14.22 million current and former customers. The company also said that some of the passwords were stored in an encrypted format, and so will be inaccessible for the hackers, but the company did not say how many were stored in this manner.</p><p>Since discovering the breach, KDDI has also been working alongside the affected ISPs to secure systems and put in place mitigation measures to counter the abuse of exposed account credentials.</p><p>In order to stay protected, customers have been advised to change their account passwords and implement two-factor authentication.</p><p>Breaches such as these are particularly dangerous because they expose email and password combinations. As most people will have either one or two email addresses across their accounts, it increases the likelihood that hackers can attempt to use the exposed email and password combinations to try and access other accounts created with the same email.</p><p>This is especially true if the same password (or a variant thereof) is used across multiple accounts. Hackers can use brute force techniques to try hundreds of password combinations in a very short amount of time in order to crack weak or reused passwords.</p><p>When creating or updating a password for any account, no matter how infrequently it is used, always create a strong unique password. <a href="https://www.techradar.com/best/password-manager" target="_blank">Password managers</a> can create and suggest strong passwords, securely store them, and automatically fill login forms to take the hassle out of remembering passwords. </p><p>Alternatively, some services offer the ability to login using a <a href="https://www.techradar.com/pro/passwords-out-passkeys-in-the-future-of-secure-authentication" target="_blank">passkey</a>, which utilizes the built-in biometric authentication mechanisms of your device such as a facial scan or fingerprint. These login methods not only remove the need to type in passwords, but also reduce the possibility of hackers accessing your account through phishing attacks.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out — that income tax form could actually be dangerous malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/watch-out-that-income-tax-form-could-actually-be-dangerous-malware</link>
                                                                            <description>
                            <![CDATA[ Researchers uncovered a fake tax notice campaign that delivered remote-access malware via staged downloads and encrypted communications. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qR5LQKebhB7ovBuobVQom</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AAnrrKYFEkWSGnT672jgVH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 28 Jun 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AAnrrKYFEkWSGnT672jgVH-1280-80.jpg">
                                                            <media:credit><![CDATA[financialcrimeacademy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Income tax fraud]]></media:description>                                                            <media:text><![CDATA[Income tax fraud]]></media:text>
                                <media:title type="plain"><![CDATA[Income tax fraud]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AAnrrKYFEkWSGnT672jgVH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Fake tax notices are becoming delivery vehicles for sophisticated remote access malware</strong></li><li><strong>Attackers hide malicious code behind convincing government branding and legal references</strong></li><li><strong>The malware quietly establishes encrypted communication with servers outside the country</strong></li></ul><p>A new phishing campaign is using fake income tax assessment notices to deliver dangerous malware to unsuspecting victims across India.</p><p>Researchers at <a href="https://www.cyfirma.com/research/an-income-tax-assessment-notice-phishing-campaign-delivering-malware/" target="_blank">CYFIRMA</a> identified the operation, which relies on a fraudulent website built to resemble official communication from the Indian Income Tax Department closely.</p><p>The fake portal, hosted on a recently registered domain, presents a convincing assessment order complete with legal references, financial penalties, and urgent compliance language designed to pressure recipients into acting quickly.</p><h2 id="how-the-infection-unfolds">How the infection unfolds</h2><p>Victims who interact with the fake notice are prompted to download a ZIP archive disguised as official assessment documentation and supporting calculations.</p><p>Once extracted, that archive reveals a disk image file functioning as a container for the actual malicious payload.</p><p>Inside sits a loader program that quietly triggers a second component, a DLL file disguised to resemble a legitimate Windows service.</p><p>Researchers found that this loader uses reflection-based techniques specifically built to make automated detection and analysis considerably more difficult.</p><p>Both files were obfuscated using a known protection tool, further complicating efforts by security teams to inspect the code.</p><p>Once active, the payload behaves like a Remote Access Trojan, granting attackers persistent, encrypted access to the infected machine.</p><p>It can collect system details, monitor user activity, check which security software is installed, and silently load additional malicious components on command.</p><p>Communication with the attacker's server happens over an encrypted channel, using a hardcoded address traced to infrastructure based in Hong Kong.</p><p>These capabilities point toward a financially motivated operation, rather than one focused on immediate damage or disruption, and they closely resemble traits associated with known commodity RAT families such as XWorm.</p><p>However, researchers note that conclusive attribution to a specific threat actor remains unconfirmed at this stage.</p><h2 id="why-this-campaign-matters">Why this campaign matters</h2><p>This is not an isolated phishing attempt but part of a broader pattern of attackers exploiting tax season anxiety to bypass user caution entirely.</p><p>CYFIRMA's findings show the same loader-and-payload architecture has previously been linked to <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> operators, suggesting this infrastructure may serve more than one type of attack depending on the victim.</p><p>Up-to-date <a href="https://www.techradar.com/best/best-antivirus">antivirus software</a> with behavioral detection remains one practical defence against this kind of staged, multi-component <a href="https://www.techradar.com/best/best-malware-removal">malware</a> delivery.</p><p>Security researchers recommend that individuals verify any tax-related correspondence directly through official government channels rather than clicking embedded links.</p><p>Organizations are advised to restrict the execution of unknown files arriving through archives or disk images, since this campaign relies heavily on that exact delivery method to succeed.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GTA VI fans beware — experts warn 'a new wave of scam websites' is offering early access, but just stealing your bank details instead ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/gta-vi-fans-beware-experts-warn-a-new-wave-of-scam-websites-is-offering-early-access-but-just-stealing-your-bank-details-instead</link>
                                                                            <description>
                            <![CDATA[ Cybercriminals are exploiting GTA VI anticipation with fake beta programmes designed to steal money, credentials, and personal information. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RkCkYdUg2ZHeUHU4pa3vaS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EweZxK8eSVuvCSALvxaDL5-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sat, 27 Jun 2026 23:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/EweZxK8eSVuvCSALvxaDL5-1280-80.png">
                                                            <media:credit><![CDATA[Malwarebytes]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GTA VI fake websites are now everywhere — be warned]]></media:description>                                                            <media:text><![CDATA[GTA VI fake websites are now everywhere — be warned]]></media:text>
                                <media:title type="plain"><![CDATA[GTA VI fake websites are now everywhere — be warned]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EweZxK8eSVuvCSALvxaDL5-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Fake GTA VI beta keys are already draining cryptocurrency wallets worldwide</strong></li><li><strong>AI-generated scam websites now imitate Rockstar branding with alarming accuracy</strong></li><li><strong>Malware hidden inside fake game downloads can expose banking credentials instantly</strong></li></ul><p>Grand Theft Auto VI is not due on consoles until November 19 2026, but official preorders open soon, and cybersecurity researchers have warned criminals are already exploiting the wait with a coordinated wave of fraudulent websites.</p><p>Malwarebytes and NordVPN have both flagged sites promising "VIP early access" or exclusive beta keys to one of gaming's most anticipated releases.</p><p>The schemes ask victims to hand over money, personal information, or both, often before any real product changes hands.</p><h2 id="how-the-scam-works">How the scam works</h2><p>Some fraudulent sites ask players to pay a few hundred dollars in cryptocurrency for a so-called VIP beta key. This method makes refunds or fraud reports practically impossible once the payment clears.</p><p>According to Stefan Dasic of Malwarebytes, GTA VI is "the perfect bait" that can be used by cybercriminals.</p><p>The franchise sold hundreds of millions of copies and went 13 years without a new entry — conditions that make hype, and therefore impatience, unusually intense.</p><p>Gerald Kasulis of NordVPN said scammers now use AI to mimic Rockstar's official branding so convincingly that polished emails and websites slip past a gamer's usual scepticism.</p><p>Some pages invoke the phrase "help us build Vice City," a reference to the game's fictional setting, to create a false sense of insider access.</p><p>Victims are sometimes directed to download software branded as an early build, including one fake file called GTA Mobile 6.</p><p>According to researchers, this file contains <a href="https://www.techradar.com/best/best-malware-removal">malware</a> capable of letting fraudsters remotely access the victim's device, often bypassing <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> software.</p><p>NordVPN has separately traced some of these fraudulent domains to a wider network with a documented history of spreading banking trojans, infostealers, and <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a>.</p><p>Other variants simply harvest names, addresses, dates of birth, or existing GTA login credentials, data that can then be resold.</p><p>Several of these scam sites even target PC and Android users, despite Rockstar never confirming that those versions exist yet.</p><h2 id="who-is-being-targeted">Who is being targeted?</h2><p>The typical victim tends to be someone too young, too eager, or simply underinformed, and primarily driven by a desire to be first in line for the game.</p><p>However, Malwarebytes' assessment of the scam wave reveals that the trick itself is rarely sophisticated, yet it consistently fools people regardless of age.</p><p>The character of those falling for these scams goes beyond simple naivety, since urgency and curiosity are what scammers are really exploiting across these campaigns.</p><p>Younger players and newcomers to online gaming appear especially exposed, given their relative unfamiliarity with how official preorder and beta access processes normally function.</p><p>Neither company has data on exactly how many people have visited these sites or lost money so far.</p><p>Rockstar Games has not responded to requests for comment on the ongoing scam wave or its impact on players.</p><p>Security researchers are urging anyone tempted by claims of early GTA VI access to pause and verify the source before entering any personal or financial details.</p><p>Players who have already entered credentials or payment information are advised to change their passwords immediately.</p><p>They should also contact their bank without delay, since cryptocurrency payments in particular cannot be reversed once sent. </p><p>Via <a href="https://www.pcgamer.com/games/grand-theft-auto/grand-theft-auto-6-vip-early-access-scam-sites-are-already-popping-up-malwarebytes-warns/" target="_blank" rel="nofollow">PCGAMER</a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Unnamed hackers steal stolen data from Icarus hackers responsible for Klue supply chain hack — and yes, it's as confusing as it sounds ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/unnamed-hackers-steal-stolen-data-from-icarus-hackers-responsible-for-klue-supply-chain-hack-and-yes-its-as-confusing-as-it-sounds</link>
                                                                            <description>
                            <![CDATA[ Klue was hacked by Icarus, and then Icarus was hacked by another group. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dn5yZH8XeXT5eSKjpEMKUe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Jun 2026 13:27:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Klue recently suffered a cyber attack at the hands of Icarus</strong></li><li><strong>Icarus was apparently deleting the stolen customer data</strong></li><li><strong>An unnamed group claims to have stolen the data from Icarus, and is now extorting Klue customers directly</strong></li></ul><p>Earlier this month, market research provider Klue suffered a cyberattack with the knock-on effects <a href="https://www.techradar.com/pro/security/lastpass-confirms-data-breach-after-hacker-compromises-supply-chain-heres-what-we-know" target="_blank">hitting major companies such as LastPass</a>, Gong, Jamf, HackerOne, Huntress and others.</p><p>Klue has since revealed it is in contact with the Icarus ransomware group, who claim to have been in possession of stolen data and were threatening to leak the data in an attempt to extort the company.</p><p>But a second, unnamed group has emerged, which claims to have broken into a member of the Icarus group’s environment to steal the customer data stolen by Icarus from Klue. This second group is now apparently attempting to extort Klue customers directly, much to the annoyance of Icarus.</p><h2 id="hackers-hacked-by-hackers">Hackers hacked by hackers</h2><p>An update shared privately with Klue customers on Wednesday night and seen by <a href="https://techcrunch.com/2026/06/25/hacked-klue-says-criminals-are-deleting-stolen-customer-data-but-now-other-hackers-are-making-threats/" target="_blank"><em>TechCrunch</em></a> said, “We continue to communicate with the threat actor we have been in contact with (‘Icarus’). Icarus told us they are taking steps to delete the data taken from Klue customers. The Icarus site remains down and we have indications that Icarus is indeed taking steps to delete data taken from Klue customers.”</p><p>Icarus later informed Klue that the second group was attempting to extort Klue customers using the same data, having posted a list of affected companies on its own website. Alongside this list, they also claimed to have stolen the customer data from Icarus, after one of the Icarus group accidentally allowed the group to connect to the server hosting the stolen data.</p><p>Although there is no evidence that Klue has paid the Icarus group, the unnamed group also posted a statement that an “Icarus operator who is a teenager living somewhere in the UK or adjacent countries” had been paid by Klue to delete the stolen data.</p><p>A further communique issued by Klue to its customers said that it had been reassured by Icarus that the unnamed group only had samples of the stolen data, not the full set. It also said that, “Icarus has asked us to inform Klue customers to not make payment to this other party.”</p><p>Klue also suggested that its customers should ask the second group for random samples of their data to prove whether or not they actually had obtained the full set of stolen customer data.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Travelers are getting better at spotting obvious scams' — but experts warn Airbnb scams are on the rise as summer arrives ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/travelers-are-getting-better-at-spotting-obvious-scams-but-experts-warn-airbnb-scams-are-on-the-rise-as-summer-arrives</link>
                                                                            <description>
                            <![CDATA[ As summer travel peaks, experts warn of Airbnb scams exploiting verified host accounts to trick users into fake vacations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7XmXUDBXn3r3R4jkjMNZ8j</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TTY5Kw4XBVMnVyegXQfgGT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Jun 2026 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TTY5Kw4XBVMnVyegXQfgGT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Iryna Kalamurza]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Young couple planning honeymoon vacation trip with map]]></media:description>                                                            <media:text><![CDATA[Young couple planning honeymoon vacation trip with map]]></media:text>
                                <media:title type="plain"><![CDATA[Young couple planning honeymoon vacation trip with map]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TTY5Kw4XBVMnVyegXQfgGT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Airbnb scams have surged 30x since 2023, including a sharp rise this year</strong></li><li><strong>Criminals hijack legitimate host accounts to to trick holidaymakers</strong></li><li><strong>Staying safe isn't so straightforward as threats evolve</strong></li></ul><p>Airbnb-related scam activity has increased 30x since the first half of 2023, according to new research from Saily and NordStellar, confirming that cybercriminals continue to go after holidaymakers seeking the best deals amid rising prices.</p><p>The report ultimately concludes that attackers are now targeting the trust built by larger platforms, saving them from having to build new identities from scratch.</p><p>And to top it all off, the nature of scams is also changing, as instead of using suspicious websites to obtain victim payments or information, criminals are now targeting legitimate Airbnb host accounts which have spent years amassing positive reviews and high ratings.</p><h2 id="exploiting-legitimate-accounts-and-hijacking-trust">Exploiting legitimate accounts and hijacking trust</h2><p>While the end goal remains high volumes of vulnerable consumers, scammers have added an extra layer of victim in their pipeline. Verified Airbnb hosts are now valuable assets for criminals because they already have identity verifications, positive reviews, booking histories, years of activity and established credibility.</p><p>Once the verified account is compromised, attackers can then go on to scam higher volumes of unsuspecting victims by posting – and charging for – fake property listings.</p><p>“Travelers are getting better at spotting obvious scams,” Saily Head of Product Matas Cenys said. “Criminals know this, so they are increasingly trying to steal trust instead of building fake trust from scratch.”</p><p>Where this type of attack differs from others, though, is that the victims never leave the platform. Rather than falling victim to phishing attacks and being redirected to malicious external sites, they interact fully with supposed legitimate hosts on the Airbnb platform.</p><p>While Airbnb attacks have seen a 30x increase in around three years and a sharp rise in the last year alone, they reflect a much broader trend of attackers compromising existing trusted accounts.</p><p>The recent ramp-up in attacks could also be tied to the summer season, with holidaymakers looking to book last-minute deals in the run-up to the summer season. Urgency and pressure to keep costs low also adds to criminals’ success.</p><p>“Everything looks normal until they arrive at their destination and discover the accommodation never existed," Cenys added.</p><h2 id="how-to-protect-yourself-from-booking-scams">How to protect yourself from booking scams</h2><p>Saily is recommending that all communication stays within the booking platform and that customers avoid payment methods suggested outside of official channels. Unusually attractive listings in high-demand destinations could also be taken with a pinch of salt, and savvy shoppers may choose to reverse image search a property to double check its authenticity.</p><p>“As travel booking becomes increasingly digital, trust becomes one of the most valuable currencies in the travel ecosystem,” Cenys warned.</p><p>As for abusing victim trust, researchers also argue that AI has aided attacks by allowing criminals to produce better fake listings more quickly.</p><p>More generally, Airbnb revealed that two in five Americans have fallen victim for an online scam, with the average loss totalling nearly $2,000. The company has introduced measures to remind its users how to avoid scams, including introducing identity verification and reminders not to leave the platform, but account takeovers can still slip under the radar.</p><p>Airbnb also holds guest payments until 24 hours after check-in to ensure that everything is as described. Anti-fraud tech also prevented around 265,000 suspicious listings from appearing on the platform in 2025, the company boasted.</p><p>The company <a href="https://news.airbnb.com/partnering-with-experts-on-tips-to-help-avoid-summer-travel-scams-in-u-s/" target="_blank">posted</a> a comprehensive eight-step list of how to avoid scams on its platform online, calling out pressure tactics and unusual deals.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A newbie hacker used "vague, low-skill prompts" in Claude and Codex to breach 14 companies, and the AI Agents did all the legwork ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-newbie-hacker-used-vague-low-skill-prompts-in-claude-and-codex-to-breach-14-companies-and-the-ai-agents-did-all-the-legwork</link>
                                                                            <description>
                            <![CDATA[ A newbie hacker is still a newbie hacker, though, and this one left a few gaping holes in his work. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VMRSV9yYEZbm4Lkvnzczmn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 14:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:description>                                                            <media:text><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:text>
                                <media:title type="plain"><![CDATA[A robot in front of a digital screen, touching some of the symbols with its outstretched finger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Thi6y93AMWrCXJAEiHDQbL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OALABS analyzed a novice attacker’s full working directory showing 14 breaches carried out with Claude Code and Codex agents</strong></li><li><strong>Attacker used vague prompts; AI agents handled reconnaissance, exploit writing, and data harvesting, bypassing guardrails with ease</strong></li><li><strong>Logs revealed attacker’s identity and location in Addis Ababa, Ethiopia</strong></li></ul><p>A newbie cybercriminal managed to break into 14 organizations and steal sensitive data, just by using Anthropic’s Claude Code and OpenAI’s Codex agents. This is according to cybersecurity researchers OALABS, who recovered and analyzed the attacker’s entire working directory.</p><p>The researchers used this news as yet another proof that advanced Generative Artificial Intelligence (<a href="https://www.techradar.com/best/best-ai-tools" target="_blank">GenAI</a>) models are significantly lowering the barrier for entry into cybercrime, and to sound the alarm that the security community needs to step up.</p><p>“In many cases, the attacker supplied only vague, low-skill prompts and allowed Claude to fill in the gaps: researching exposed services, identifying possible vulnerabilities, writing exploit code, validating access, and harvesting data,” the researchers said. “The attacker did not need to be an expert operator; they simply had to use the correct framing for their prompts. The agent supplied much of the structure and technical execution that the attacker appeared to lack.”</p><h2 id="doxxing-the-attacker">Doxxing the attacker</h2><p>OALABS could not find evidence that the stolen data was monetized in any way, either by being sold on the dark web, or by extorting the victim companies. They did, however, find numerous pieces of evidence about the attacker’s identity and whereabouts.</p><p>According to the researchers, the attacker did not run the AI agents on his own infrastructure, but rather on a third-party server, and when that third party discovered malicious activity, they downloaded the entire working directory and shared it with the researchers.</p><p>“Because the agents were local to the host, their full session logs were recovered, including the attacker’s prompts, the tools used, the internal monologue of the large language model (LLM), and any policy violations recorded during the sessions,” the researchers said.</p><p>OALABS was thus able to analyze more than 1,000 agent sessions, seeing how the attacker was able, with ease, to bypass most of the agents’ guardrails. Among the sessions were also the threat actor’s CV with his full name, location, education history, and LinkedIn profile, as well as his IP address which showed that he was located in Addis Ababa, Ethiopia.</p><p><em>Via </em><a href="https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/" target="_blank"><em>Helpnet Security</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘I barely slept last night’: Hackers sent an ‘extreme’ alert to millions of Brazilians using the government’s own tools, and that’s a huge concern ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/computing/cyber-security/i-barely-slept-last-night-hackers-sent-an-extreme-alert-to-millions-of-brazilians-using-the-governments-own-tools-and-thats-a-huge-concern</link>
                                                                            <description>
                            <![CDATA[ Hackers breached government systems in Brazil to send millions of people a mysterious ‘extreme’ alert. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xzHZArtxfXsF9o77iA4yhc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ui7eDjrVhqovuAQCCWrpkF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Jun 2026 11:56:22 +0000</pubDate>                                                                                                                                <updated>Mon, 22 Jun 2026 11:59:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ui7eDjrVhqovuAQCCWrpkF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two hands holding a phone showing the Brazil flag and X]]></media:description>                                                            <media:text><![CDATA[Two hands holding a phone showing the Brazil flag and X]]></media:text>
                                <media:title type="plain"><![CDATA[Two hands holding a phone showing the Brazil flag and X]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ui7eDjrVhqovuAQCCWrpkF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Millions of Brazilians received an unauthorized government alert</strong></li><li><strong>The text simply read ‘misanthropi4’ and it’s unknown who sent it</strong></li><li><strong>The government has denied it was responsible, pointing towards hackers</strong></li></ul><p>If you’re based in the US, you might know about AMBER alerts, also known as <a href="https://www.techradar.com/phones/android/your-android-phone-just-got-better-at-saving-your-life-heres-how">Wireless Emergency Alerts</a>, which are mass-broadcast messages sent to every <a href="https://www.techradar.com/news/best-phone">smartphone</a> in a designated area. Several other nations have similar platforms in place, including Brazil — but many Brazilians recently learned that their emergency alert system wasn’t quite as secure as they might have hoped.</p><p>In the early hours of Saturday morning, millions of Brazilians were jolted awake by a mysterious message from the country’s alert system. The alert level was classified as “extreme,” and concerningly, it’s thought it was the work of <a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know">hackers</a> rather than any official body. </p><p>The message, which was sent to civilians in the southern state of Paraná and the cities of São Paulo and Rio de Janeiro, among others, simply read “misantropi4.” That’s an approximation of the Portuguese word “misanthropia,” (with the final A swapped for a 4). As with the English word “misanthropy,” it means a hatred or distrust of humanity. </p><p>The message was accompanied by a loud alarm sound normally reserved for particularly severe thunderstorms. Since the text was sent shortly after midnight local time, it ensured that many people were woken up in the middle of the night. </p><p>Brazilian authorities said that the emergency message system was taken offline after a probable hacker attack, suggesting that this was more than just a simple text sent out in error by the government. Indeed, there was no event or natural disaster serious enough to warrant the alert being activated at the time, which further points towards bad actors being responsible.</p><h2 id="a-potentially-devastating-attack">A potentially devastating attack</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:738px;"><p class="vanilla-image-block" style="padding-top:56.23%;"><img id="3yJ4ZzG7h8cwpxdMsAJVqf" name="Brazil hackers alert system by BrazilianSwainSimp" alt="An alert sent by hackers to users in Brazil." src="https://cdn.mos.cms.futurecdn.net/3yJ4ZzG7h8cwpxdMsAJVqf.jpg" mos="" align="middle" fullscreen="" width="738" height="415" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">An example of the text sent by hackers to Brazilian civilians. </span><span class="credit" itemprop="copyrightHolder">(Image credit: BrazilianSwainSimp on Reddit)</span></figcaption></figure><p>The fact that hackers were able to breach a government system that has the potential to communicate with every mobile device in a given area of the country has worrying implications, both for the ways civilians could be manipulated and for the security of government institutions as a whole. </p><p>A text from a known government source is likely to be trusted more than one from an unknown number. With access to Brazil’s emergency broadcast system, hackers could potentially send out fraudulent messages that might have a larger impact than normal. That opens the door for all kinds of nefarious activities. </p><p>For now, this attack seems to have had a relatively minor impact. For many Brazilians posting on social media, the text was confusing more than anything else. </p><p><a href="https://www.reddit.com/r/mildlyinfuriating/comments/1uay1mi/comment/ossr3lj/" target="_blank">Last-Educator3947 on Reddit</a>, for example, said “I live in the town where the alert was first sent. It happened five minutes after the Brazil x Haiti <a href="https://www.techradar.com/how-to-watch/football/world-cup-2026-free">World Cup</a> game. My anxious brain associated misanthropy with a violent attack on the people celebrating in the streets after the game. I thought it was an incel <a href="https://www.techradar.com/computing/social-media/discord-just-made-your-voice-and-video-calls-more-private-and-secure-than-ever-but-age-verification-privacy-concerns-havent-been-dispelled">Discord</a> hacker sending a message to start a ‘The Purge’-style attack.” They then added: “I’m laughing now but I barely slept last night.” </p><p>Reddit user <a href="https://www.reddit.com/r/mildlyinfuriating/comments/1uay1mi/comment/osrt6os/" target="_blank">Magnon</a>, meanwhile, summed up the situation by saying that it, “Sounds like an anime villain just spawned.” </p><p>According to the <a href="https://x.com/IntCyberDigest/status/2068633434591830290" target="_blank">International Cyber Digest newsletter</a> on X, this breach could be linked to a previous hack of a Brazilian government employee who was infected with an <a href="https://www.techradar.com/pro/security/mac-users-beware-this-devious-new-infostealer-malware-disguises-itself-as-official-apple-tools-to-lure-in-victims">infostealer</a>. International Cyber Digest claims that stolen credentials included government logins, emails, developmental and staging environments, and more. </p><p>Whether or not this is what gave hackers access to the Brazilian government’s alert system isn’t yet known. Either way, it demonstrates the power that hackers can accrue if they find a way into supposedly secure governmental systems. While this alert saga turned out to be relatively harmless, that might not be the case next time.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Simply being aware is no longer sufficient protection' — Security experts warn of AI-boosted scam campaigns that can trick even the smartest victims ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/simply-being-aware-is-no-longer-sufficient-protection-security-experts-warn-of-ai-boosted-scam-campaigns-that-can-trick-even-the-smartest-victims</link>
                                                                            <description>
                            <![CDATA[ AI-powered scams are tricking victims faster than ever, with many losing money within minutes through convincing fake identities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">obwCopPAjiwsGxFGYVXNPf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vaZaSfPx7aqf7NQMxSW9i9-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 21 Jun 2026 08:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/vaZaSfPx7aqf7NQMxSW9i9-1280-80.png">
                                                            <media:credit><![CDATA[Kaspersky]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man looking at phone after being scammed by an AI tool]]></media:description>                                                            <media:text><![CDATA[Man looking at phone after being scammed by an AI tool]]></media:text>
                                <media:title type="plain"><![CDATA[Man looking at phone after being scammed by an AI tool]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vaZaSfPx7aqf7NQMxSW9i9-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Nearly two-thirds of victims believe AI tools enabled their fraud experience</strong></li><li><strong>One in ten victims handed over money within just five minutes</strong></li><li><strong>Scammers moved across multiple platforms in 63% of incidents</strong></li></ul><p>Messaging scams are becoming increasingly sophisticated as criminals use AI to imitate trusted people, familiar brands, and everyday conversations.</p><p>New <a href="https://media.kasperskydaily.com/wp-content/uploads/sites/92/2026/05/27050022/The_Great_Messaging_Heist_Report_2026_by_Kaspersky.pdf?kaspr=x75y" target="_blank" rel="nofollow">research</a> from Kaspersky suggests these schemes are succeeding with alarming speed, often convincing victims to hand over money within minutes.</p><p>The findings indicate that digital experience alone may no longer provide reliable protection against modern fraud attempts.</p><h2 id="ai-powered-scams-are-becoming-faster-and-more-convincing">AI-powered scams are becoming faster and more convincing</h2><p>The study found that nearly two-thirds of scam victims globally, or 64.5%, believed <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> played a role in the fraud attempts directed at them.</p><p>In the United Kingdom, 54% of respondents suspected criminals used deepfakes or synthetic voices to impersonate relatives, friends, or legitimate organizations, allowing scammers to create convincing scenarios that closely resemble genuine interactions and trusted relationships.</p><p>According to the research, more than half of UK victims completed payments or shared sensitive information within 30 minutes of initial contact.</p><p>More than 1 in 10 victims, representing 12.2%, did so within 5 minutes, demonstrating how rapidly these operations unfold.</p><p>Researchers also found nearly two-thirds (63%) of incidents moved across multiple communication platforms, helping fraudsters maintain credibility while avoiding suspicion.</p><p>The most common scams involved investment opportunities, affecting 40% of respondents, followed by fake delivery alert at 38% and brand impersonation schemes at 35%.</p><p>Dr. Elisabeth Carter, forensic linguist and criminologist at Kingston University London, said fraudsters create situations that appear entirely reasonable at the time.</p><p>“Fraudsters use recognised contexts, familiar social settings and embedded linguistic norms to make victims feel their decision-making is rational and reasonable in the moment,” Carter explained.</p><p>“What is actually happening is that they construct false realities in which those decisions end up causing financial and psychological harm.”</p><h2 id="financial-losses-continue-to-grow-as-reporting-remains-low">Financial losses continue to grow as reporting remains low</h2><p>The financial consequences extend beyond isolated incidents, particularly during a period when many households already face economic pressures.</p><p>Kaspersky found that victims in the UK lose an average of £458.45 per scam, while 9.1% reported losses exceeding £1,000, with more than a quarter (28%) saying they experienced three or more scam attempts within six months.</p><p>Researchers noted that millennials were especially vulnerable to investment-related fraud, with 40% reporting exposure to financial opportunity schemes.</p><p>The study also found over half (52%) of all scams occurred during the previous five months, suggesting the problem continues to accelerate rather than stabilize.</p><p>Marc Rivero, Lead Security Researcher at Kaspersky's Global Research and Analysis Team, warned that criminal groups are operating at an unprecedented scale.</p><p>“AI is accelerating the trend, helping scammers convincingly imitate brands, familiar voices, and personal relationships,” said Marc Rivero, Lead Security Researcher at Kaspersky's Global Research and Analysis Team.</p><p>“Simply being aware is no longer sufficient protection. People need to recognise risks earlier, before being pressured into hasty decisions."</p><p>Security specialists recommend combining caution with technical safeguards, including <a href="https://www.techradar.com/best/best-antivirus">antivirus software</a> capable of detecting malicious links in real time.</p><p>They also encourage stronger credential protection through a <a href="https://www.techradar.com/best/password-manager">password manager</a> and broader awareness of evolving scam tactics.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 100 days after the Iran war started — Tehran-backed group breaches California Water Service but claims they 'chose not to disrupt water access' ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/100-days-after-the-iran-war-started-tehran-backed-group-just-breached-california-water-service-but-claims-they-chose-not-to-disrupt-water-access</link>
                                                                            <description>
                            <![CDATA[ Iranian-linked group Handala breached California Water Service, leaking 5GB of customer data and exposing critical GPS infrastructure across seven districts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GEad45HVtqTWmprj8U73pV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Jun 2026 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png">
                                                            <media:credit><![CDATA[Veolia]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:description>                                                            <media:text><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:text>
                                <media:title type="plain"><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Iranian hackers accessed two Cal Water systems and leaked 5GB of data</strong></li><li><strong>A poorly secured GPS tool gave attackers a direct path inside Cal Water</strong></li><li><strong>Administrative credentials for seven California districts were published in plaintext online</strong></li></ul><p>Tehran-linked threat group Handala has claimed it successfully breached California Water Service and released a 5GB data dump as proof.</p><p>Cal Water is one of the largest investor-owned water utilities in the United States, serving millions of residential and commercial customers across California.</p><p>Handala described the breach as direct retaliation for recent US military actions in Iran, claiming it could disrupt water access but deliberately chose not to — for now.</p><h2 id="how-a-gps-tool-became-the-entry-point">How a GPS tool became the entry point</h2><p>Cybersecurity firm Dataminr analyzed the published data and identified two separate systems that Handala accessed during the breach.</p><p>The first was a customer billing database containing names, addresses, phone numbers, account numbers, and payment histories across multiple Cal Water districts.</p><p>The second was an internal RTKBase deployment — an open-source GPS base station platform used by field crews maintaining water infrastructure across California.</p><p>The RTKBase instance had been running continuously for approximately 783 hours at the time of access, with GPS correction data streaming across seven identified Cal Water districts.</p><p>Those districts included Bakersfield, Chico, Salinas, Stockton, Visalia, San Mateo, and a regional engineering segment spread across California.</p><p>The researchers believe that the GPS platform was not the end goal — it was the entry point into deeper infrastructure.</p><p>The RTKBase web interface was accessible via standard HTTP port 10000 across multiple district locations, making it straightforward for outside actors to locate and access.</p><p>It was deployed on lightweight hardware that offered minimal resistance against unauthorized entry from the internet.</p><p>Administrative credentials for the platform appeared in the published dump in plaintext, giving anyone who downloaded it immediate access to the entire system.</p><p>Full network infrastructure details for all seven districts were equally exposed, leaving Cal Water's security team with virtually nothing intact to protect.</p><h2 id="a-pattern-that-should-concern-every-water-utility">A pattern that should concern every water utility</h2><p>Handala's history makes the "chose not to disrupt" framing worth treating with considerable skepticism from any serious security perspective.</p><p>The group deployed a destructive wiper against Stryker in March 2026 that disrupted manufacturing and shipping — following the same data-theft-first pattern documented in this breach.</p><p>"Handala's operational pattern frequently involves an initial claim followed by escalated action," Dataminr's report concluded.</p><p>"Security teams should treat the current disclosure as a possible precursor to a destructive follow-on and posture accordingly."</p><p>The US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory this year warning of Iranian groups targeting US water sector technologies.</p><p>This breach is an indication that Iranian cyber threats to US water infrastructure are no longer theoretical.</p><p>Cal Water has not publicly acknowledged the breach, but affected customers now face elevated phishing risks given that their names, addresses, phone numbers, and account details are publicly available. </p><p>Via <a href="https://securityaffairs.com/193565/uncategorized/iran-linked-handala-breached-a-california-water-utility-it-could-have-done-worse-and-it-knows-that.html" target="_blank" rel="nofollow">Security Affairs</a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authentication</link>
                                                                            <description>
                            <![CDATA[ Kali365 abuses the current OAuth device code flow on Microsoft accounts in a sophisticated attempt to dupe users into signing into their accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3TQ2FNepmP2KaHKXkWEM34</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:description>                                                            <media:text><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:text>
                                <media:title type="plain"><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kali365 is a sophisticated phishing-as-a-service platform, also known as Octopi365 and Freedom365, that targets Microsoft accounts</strong></li><li><strong>It was first detected by security firm Huntress in May 2026 when examining a slew of Microsoft 365 logins originating from China</strong></li><li><strong>The FBI issues a warning detailing the process as part of a public service announcement</strong></li></ul><p>Phishing attacks are hardly new, with an estimated 3.4 billion malicious emails sent daily, accounting for a mammoth 1.2% of all email traffic.</p><p>Google alone blocks approximately 100 million phishing emails daily, as threat actors continue to evolve their approaches, using unique campaigns, AI-generated content, and, lately, QR codes to lure unsuspecting victims.</p><p>A recent phishing-as-a-service toolkit <a href="https://www.huntress.com/blog/kali365-device-code-phishing-kit" target="_blank">detected by cybersecurity company Huntress</a>, however, stands out for its sophistication, scale, and success rate.</p><h2 id="a-sophisticated-phishing-service-for-hire">A sophisticated phishing service for hire</h2><p>What makes Kali365 unique versus its peers is the scale at which it operates and the methods it uses. Unlike most phishing operations, it is a tool with at least 33 built-in templates that impersonate Microsoft products and services, 100 API endpoints, and role-based access control for phishing teams.</p><p>In addition to being an AI-enabled phishing, it also has a sophisticated payout pipeline, a crypto payment gateway integration, tiered access to the software suite, and, for those looking for a complete offering, a desktop application for operators.</p><p>Kali365 and its variants and clones, such as Octopi365 and Freedom365, do not, however, directly compromise or bypass MFA; instead, they use a set of highly legitimate emails and calls to action that then steal session cookies and OAuth tokens, allowing access to a victim's account.</p><p>The process itself is seamless; a potential victim sees a Microsoft website, an SSL certificate, and no warnings that they are effectively handing over access to a bad actor, who then uses their authenticated token to access their account. The AI-generated lures themselves are sophisticated, but as the <a href="https://www.ic3.gov/PSA/2026/PSA260521" target="_blank">FBI points out</a>, they still require a user to be phished via email, with many impersonating "trusted cloud productivity and document-sharing services."</p><p>The more damning use of AI, however, is where Anthropic's Claude AI model is used to read intercepted email threads, score them for fraud potential, and draft convincing reply messages, complete with fabricated banking details and a manufactured sense of urgency, to be sent from the victim's own mailbox. </p><p>While the FBI's warning stands, it also somewhat acknowledges that this is not an easy phishing attempt to avoid, given the scale, the multitude of phishing attack vectors, and the "legitimate" look it has compared to most of its competition. Resolving this would require a change on Microsoft's end to close security loopholes that enable such authentication transfers, but for now, any affected individuals can only <a href="https://www.ic3.gov/" target="_blank">report their experiences here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'These attacks don't look like break-ins' — HP warns hackers are turning popular remote access tools into dangerous, stealthy backdoors ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/these-attacks-dont-look-like-break-ins-hp-warns-hackers-are-turning-popular-remote-access-tools-into-dangerous-stealthy-backdoors</link>
                                                                            <description>
                            <![CDATA[ HP's latest threat report reveals hackers are abusing legitimate remote access tools and fake downloads to silently compromise corporate devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p59kSjYoTKzZrhc4SYFBwm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/abAdPvAymwxfL59qPnT4in-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2026 20:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/abAdPvAymwxfL59qPnT4in-1280-80.jpg">
                                                            <media:credit><![CDATA[ozrimoz / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker]]></media:description>                                                            <media:text><![CDATA[Hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/abAdPvAymwxfL59qPnT4in-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Legitimate software is now the most dangerous weapon in a hacker's arsenal, HP warns</strong></li><li><strong>Tax deadline phishing emails are opening doors that security scanners never flag</strong></li><li><strong>Fake dating app downloads are delivering full remote access to attackers instantly</strong></li></ul><p>Cybercriminals are exploiting legitimate remote access applications such as LogMeIn and ScreenConnect to take control of victim devices without triggering standard security alerts, experts have warned.</p><p>HP's latest <a href="https://www.hp.com/us-en/newsroom/press-releases/2026/HP-attackers-are-turning-legitimate-remote-access-tools-into-backdoors.html" target="_blank" rel="nofollow">Threat Insights Report</a>, covering January through March 2026, documents how attackers are deliberately blending malicious activity into normal IT behavior to avoid detection.</p><p>The report draws on data from millions of endpoints running HP Wolf Security across the period under review, and found the campaigns follow a consistent pattern built around social engineering rather than technical exploits.</p><h2 id="how-trust-becomes-the-weapon">How trust becomes the weapon</h2><p>Legitimate software becomes the perfect disguise precisely because security tools are least likely to flag applications they already recognize and trust.</p><p>When an attacker controls a familiar remote access tool on a victim's device, nothing in the security stack raises an alarm.</p><p>That invisibility starts at the very first step — attackers used tax year-end phishing <a href="https://www.techradar.com/news/best-email-provider">emails</a> and fake desktop application downloads, including fraudulent dating website installers, to persuade users into installing remote access tools that they control.</p><p>Once installed, those tools gave attackers total device control while appearing indistinguishable from routine IT activity.</p><p>"What stands out in these campaigns is how easily legitimate remote access tools are being turned into entry points for attackers," said Patrick Schläpfer, Principal Threat Researcher at HP Security Lab.</p><p>"By combining trusted software with carefully designed social engineering — tied to events like the end of the tax year — it's getting even harder to distinguish what can and can't be trusted."</p><p>Separate campaigns uncovered in the same period used fake cryptocurrency wallet recovery tools distributed through code-sharing platforms and media download sites.</p><p>Those tools, rather than helping users recover lost wallets, harvested credentials, wallet data, and system information before packaging everything into archive files for exfiltration.</p><p>The emoji-heavy scripts used in these attacks showed characteristics consistent with AI-assisted coding.</p><p>This suggests that <a href="https://www.techradar.com/pro/best-vibe-coding-tools">vibe coding tools</a> are now lowering the barrier for building functional malware.</p><h2 id="malware-hides-in-plain-sight">Malware hides in plain sight</h2><p>HP's report also documented ClickFix campaigns disguising <a href="https://www.techradar.com/best/best-malware-removal">malware</a> as audio files through convincing fake websites and realistic CAPTCHA prompts.</p><p>Victims unknowingly execute the malicious code in the background while believing they were completing routine security checks.</p><p>At least 11% of email threats identified by HP Wolf Security during the period bypassed one or more email gateway scanners entirely.</p><p>Executable files accounted for the largest share of malware delivery at 39%, followed by archive files at 38% and PDF documents at 10%.</p><p>"These attacks don't look like break-ins — they look like business as usual, blending in with normal IT activity and avoiding the warning signs associated with malware," said Alex Holland, Principal Threat Researcher at HP Security Lab</p><p>Holland added that organizations should restrict unnecessary privileges, control software installation, and isolate risky activity such as downloads and unknown links.</p><p>Enterprise security teams are advised to adjust their defenses to account for attacks that look legitimate, rather than suspicious. </p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI gives first peek inside 22,000-square-foot town it’s built for digital crime training — the ‘one of a kind’ facility has a gas station, houses, and a data center with 200 hackable servers ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/computing/cyber-security/fbi-gives-first-peek-inside-22-000-square-foot-town-its-built-for-digital-crime-training-the-one-of-a-kind-facility-has-a-gas-station-houses-and-a-data-center-with-200-hackable-servers</link>
                                                                            <description>
                            <![CDATA[ The FBI has built a town with homes, businesses and hackable servers to help train its cyber agents. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bNAts2q82S3t2mKTdnxjmB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gfW7CHQv24GE99jKuh54CZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2026 03:46:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gfW7CHQv24GE99jKuh54CZ-1280-80.jpg">
                                                            <media:credit><![CDATA[FBI]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Buildings inside the FBI&#039;s Kinetic Cyber Range training facility.]]></media:description>                                                            <media:text><![CDATA[Buildings inside the FBI&#039;s Kinetic Cyber Range training facility.]]></media:text>
                                <media:title type="plain"><![CDATA[Buildings inside the FBI&#039;s Kinetic Cyber Range training facility.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gfW7CHQv24GE99jKuh54CZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The FBI has built an entire town to help train its agents</strong></li><li><strong>The town contains houses, businesses, and 200 hackable servers</strong></li><li><strong>The idea is to give agents hands-on experience so they’re ready for the field</strong></li></ul><p>In the never-ending cat-and-mouse game between hackers and law enforcement, it helps the latter to know exactly what they’re up against. Usually, that might mean sitting in a classroom and getting a little hands-on time with a hacked server or laptop. But that’s not the case with the FBI’s Kinetic Cyber Range — no, this time the US’s Federal Bureau of Investigation went out and built a whole town to keep itself sharp. </p><p>The 22,000-square-foot <a href="https://www.fbi.gov/news/stories/inside-the-fbis-kinetic-cyber-range" target="_blank">Kinetic Cyber Range</a> is built to be as lifelike as possible. Pay it a visit, and you’ll find 11 different facilities, including houses, a data center, a gaming arcade, a convenience store, a hotel, and much more. It’s designed to replicate the kind of town you might find anywhere in America, yet it’s all contained within an enormous hangar at the FBI’s training campus in Huntsville, Alabama. </p><p>All the businesses and tech in the ersatz community can be <a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know" target="_blank">hacked</a>, allowing students to put their skills to the test. Would-be cyber officers will encounter <a href="https://www.techradar.com/best/firewall">firewalls</a>, email systems, file directories, and more, helping to prepare them for future digital investigations. That said, the Kinetic Cyber Range is designed to ensure that nothing nefarious spills out of its secure bounds and into the wider world. </p><p>In addition to the FBI, the facility can be used by NASA, the US Army, and local law enforcement agencies. The idea is to get people up to speed with the latest cyber techs — including drone software, vehicle forensics, and the internet of things.</p><h2 id="facing-emerging-threats">Facing emerging threats</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1400px;"><p class="vanilla-image-block" style="padding-top:56.29%;"><img id="cAPxpbP4WXZ4rJur8xF6AZ" name="FBI Kinetic Cyber Range 2" alt="A person working inside the FBI's Kinetic Cyber Range training facility." src="https://cdn.mos.cms.futurecdn.net/cAPxpbP4WXZ4rJur8xF6AZ.jpg" mos="" align="middle" fullscreen="" width="1400" height="788" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: FBI)</span></figcaption></figure><p>Given how <a href="https://www.techradar.com/pro/security/fraud-wont-be-tolerated-in-this-country-any-longer-fbi-releases-most-wanted-fraudsters-list-to-help-fight-the-crime-that-costs-americans-tens-of-billions-of-dollars-every-year">incredibly lucrative</a> the cybercrime industry is for <a href="https://www.techradar.com/pro/security/scams-are-getting-so-much-more-efficient-new-study-warns-over-half-of-americans-hit-by-fraud-in-2025-and-the-figure-is-only-going-to-get-worse">hackers and fraudsters</a>, it makes sense for law enforcement to seek as much real-world, hands-on time as possible. Theory alone will only provide so much education, and without encountering the kinds of situations you might find in the real world, FBI agents will be a step behind their adversaries. </p><p>Speaking on the <a href="https://www.youtube.com/watch?v=a8UMAc_8L5c" target="_blank">FBI’s YouTube channel</a>, David Beachboard, Program Manager of the Kinetic Cyber Range, described the training location as “one of a kind” and said that “there is no facility like this in the world … This is about as real as it’s going to get before people go out in the field.” </p><p>Interestingly, students at the center will also be involved in various roleplay exercises that mimic those they’ll encounter outside the facility, from conducting interviews with business executives whose premises are being searched to dealing with medical staff who are concerned for patient welfare in the middle of a <a href="https://www.techradar.com/pro/most-ransomware-attacks-are-opportunistic-heres-how-you-can-stop-attackers">ransomware</a> attack. It’s these scenarios that are difficult or impossible to fully replicate inside a classroom. </p><p>According to the FBI, more than 1,400 students have passed through the Kinetic Cyber Range since its opening in February 2025, with the training being regularly updated to cover <a href="https://www.techradar.com/pro/how-emerging-tech-is-rewriting-cyberwarfare">emerging threats</a>. As threat actors evolve, so too must those attempting to stop them. No doubt Beachboard and the FBI hope the Kinetic Cyber Range will play a key role in doing just that.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How scammers use "scraped New York Times content" to trick security scanners — and exploit "free" Google Cloud links to flood your inbox ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/how-scammers-use-scraped-new-york-times-content-to-trick-security-scanners-and-exploit-free-google-cloud-links-to-flood-your-inbox</link>
                                                                            <description>
                            <![CDATA[ Researchers uncovered a global phishing network using Google Cloud redirects and copied news content across thousands of coordinated servers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QHPZ4FoC5h5Sim29zhDFKb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2026 23:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>More than 12,000 servers supported a coordinated phishing infrastructure worldwide</strong></li><li><strong>Google Cloud links helped phishing emails appear safer than reality</strong></li><li><strong>Fake New York Times pages acted as decoys for scanners</strong></li></ul><p>When a suspicious email lands in your inbox promising financial rewards or urgent payment requests, the infrastructure behind that email is rarely what it appears to be.</p><p>An investigation by <a href="https://www.comparitech.com/news/how-spammers-are-hiding-behind-google-and-the-new-york-times/" target="_blank" rel="nofollow">Comparitech</a> revealed a coordinated spam and phishing network spanning 12,704 servers in 55 countries.</p><p>These phishing emails are tied to fake financial rewards and similar scams, using tactics designed to evade security tools such as antivirus and <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware protection</a> systems that many users depend on.</p><h2 id="trusted-google-links-help-the-campaign-evade-detection">Trusted Google links help the campaign evade detection</h2><p>The campaign begins with unsolicited emails promoting financial rewards, health products, gambling offers, or urgent payment requests through embedded links.</p><p>Rather than directing recipients immediately to attacker-controlled websites, the links first route through Google Cloud Storage pages hosted on Google's infrastructure.</p><p>That approach matters because familiar Google domains<a href="https://www.techradar.com/pro/security/experts-warn-hackers-are-hiding-malware-inside-googles-own-ad-systems-heres-what-we-know"> generally attract less scrutiny</a> from users and automated filtering systems than unknown websites.</p><p>Google-owned URLs passed easily through email gateways, <a href="https://www.techradar.com/best/firewall">firewalls</a>, and reputation filters that routinely extend trust to Google domains without deeper inspection.</p><p>Researchers found that attackers uploaded simple HTML and JavaScript files to cloud storage locations, allowing them to redirect visitors elsewhere without placing obviously malicious content on Google's servers.</p><p>This separation between the initial link and the final destination also provides operational flexibility for campaign operators.</p><p>Redirect destinations can be changed at any time without requiring modifications to emails that have already been distributed to potential victims.</p><p>During testing, researchers repeatedly encountered nearly identical landing pages displaying news content copied from <em>The New York Times</em>.</p><p>These pages appeared designed to serve as harmless decoys for security products, researchers, and visitors who did not meet specific selection criteria.</p><p>The infrastructure supporting these pages shared common software configurations, matching asset directories, similar redirect behaviour, and largely outdated server environments.</p><h2 id="the-scale-is-difficult-to-dismiss">The scale is difficult to dismiss</h2><p>The research identified the network through a single CSS file path — assets/ayt/css/main.css — repeated identically across thousands of servers.</p><p>This pattern points to a centralized deployment rather than independent operators - of the 12,704 servers identified, 99.8% ran end-of-life software with no active security updates, spread across 412 hosting providers in dozens of jurisdictions.</p><p>That geographic spread was almost certainly deliberate — takedowns targeting one provider leave the rest of the network entirely intact.</p><p>Checking 5,000 of those servers against a crowd-sourced IP reputation database revealed that 89% carried no prior abuse history.</p><p>This suggests that the infrastructure was either recently provisioned or rotated frequently enough to stay ahead of <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> and threat intelligence systems.</p><p>Anyone who entered personal information on any page reached through one of these emails should treat that data as compromised.</p><p>Such users have to change their passwords immediately, especially where the password is reused across multiple services.</p><p>Furthermore, it is important to constantly monitor all financial accounts for unusual activities no matter how small they may appear initially.</p><p>Clicking a link without entering any information still carried a consequence. That click confirmed to the operators that the email address was live and active.</p><p>This means the email is likely to receive increased volumes of spam in the future, raising the risk of exposure to additional phishing attempts and fraudulent schemes.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korean hackers are at it again — phishing scheme targets hundreds of workers to try and steal crypto and more ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/north-korean-hackers-are-at-it-again-phishing-scheme-targets-hundreds-of-workers-to-try-and-steal-crypto-and-more</link>
                                                                            <description>
                            <![CDATA[ Lazarus is getting company as UNK_DeadDrop starts luring devs with fake jobs, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ujahv2UUX5DRFMXvby7JzP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Jun 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UNK_DeadDrop targets developers with email‑based fake job lures</strong></li><li><strong>Campaign mirrors Lazarus tactics but uses new self‑contained payloads</strong></li><li><strong>Proofpoint says shift to mass phishing shows industrialized NK ops</strong></li></ul><p>Lazarus is not the only North Korean threat actor that is luring software developers with fake jobs - there is also a hacking group called UNK_DeadDrop now doing a similar thing, but with notable differences.</p><p>Security researchers at Proofpoint published an in-depth <a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal" target="_blank">report</a> looking into an ongoing campaign not unlike the Contagious Interview one.</p><p>For those unaware of Contagious Interview, it is one of two major Lazarus campaigns, the second one being Operation DreamJob. The crooks would fake everything - a company, its employees, as well as projects, and then go to LinkedIn for a “hiring spree.” They would reach out to software developers working in high-profile AI and Web 3 organizations and would offer high-paying jobs and a chance to work on exciting new projects.</p><h2 id="similarities-and-differences">Similarities and differences</h2><p>The hiring process, however, would include a trial assignment, which often required the victims to run <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malicious code</a> from GitHub. After infecting their targets with infostealers, the crooks would access company profiles, exfiltrate crypto wallet information, and then steal as many tokens as possible. </p><p>According to some sources, <a href="https://www.techradar.com/pro/lazarus-and-kimsuky-prove-why-infrastructure-level-analysis-is-crucial-for-cybersecurity" target="_blank">Lazarus</a> alone was able to steal billions of dollars in crypto throughout the years.</p><p>While UNK_DeadDrop is more-or-less doing the same thing, its approach is somewhat different. Instead of using LinkedIn for initial contact, these attackers rely mostly on email. They don’t arrange fake interviews, but rather just send unsolicited job offers or code review requests. And finally, they use a new, self-contained payload distinct from what was previously seen in Contagious Interview campaigns. </p><p>“UNK_DeadDrop activity suggests North Korea-aligned operations targeting developers for financial gain are maturing and evolving,” Proofpoint’s researchers concluded. </p><p>“The shift from active social engineering over social media platforms to conduct fake interviews to large campaigns of recruitment-themed phishing emails distributing links to malicious repositories could indicate an actor industrializing and scaling operations.”</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/06/08/suspected-norks-send-250-fake-dev-job-pitches-to-steal-crypto/5252526" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/russian-hackers-attack-europe-for-the-motherland-in-crypto-fueled-great-patriotic-cyber-war</link>
                                                                            <description>
                            <![CDATA[ NoName057(16) launched "Patriotic Online Games", calling all hackers to participate and get paid in crypto. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fbJYxB2J8pdNQJCbNwjC7U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Jun 2026 14:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[russian flag]]></media:description>                                                            <media:text><![CDATA[russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NoName057(16) launches “Patriotic Online Games” hacking campaign</strong></li><li><strong>Targets European organizations supporting Ukraine</strong></li><li><strong>Volunteers rewarded with cryptocurrency for attacks</strong></li></ul><p>NoName057(16), a pro-Russian hacker group known for <a href="https://www.techradar.com/news/best-ddos-protection">DDoS attacks</a> against Western organizations, launched a hacking initiative to get as many cybercriminals engaged in attacks against organizations in Europe.</p><p>According to Cybersecurity Insiders, the group took to Telegram to call upon “patriotic volunteers” which would then be given specific assignments, ranging from DDoS attacks, across information-gathering missions, to ransomware. The organizers call the campaign “Patriotic Online Games”, likely to draw a larger crowd and hide the fact that this is essentially a criminal enterprise.</p><p>The targets are, first and foremost, located in European countries that voiced their support to Ukraine in its war against Russia. They include government agencies, financial institutions, and critical infrastructure organizations. Those who successfully pull off their task get paid in cryptocurrency, allegedly being paid out directly into their wallets. </p><h2 id="who-are-noname057-16">Who are NoName057(16)?</h2><p>NoName057(16) is a very active threat actor, seen running highly disruptive DDoS attacks, hits against Taiwanese critical infrastructure firms, and observed striking Italian airports.</p><p>A few months ago, the Italian government claimed it <a href="https://www.techradar.com/pro/security/winter-olympics-hit-by-suspected-russian-origin-cyberattack-as-one-of-europes-largest-universities-also-reports-major-cybersecurity-incident" target="_blank">successfully thwarted</a> a series of cyberattacks targeting the 2026 Winter Olympics in Milano Cortina. At the time, foreign Minister Antonio Tajani said the attack hit facilities connected to the 2026 Winter Games, including hotels in the Alpine resort of Cortina d’Ampezzo where athletes were staying.</p><p>The wide-ranging attack reportedly hit around 120 targets, including foreign ministry offices in the US, as well as consulates in Sydney, Toronto and Paris, and La Sapienza university in Rome was also hit in a seemingly separate attack also attributed to Russian-linked hackers.</p><p>On Telegram, NoName057(16) confirmed the victims were targeted because of Italy’s support for Ukraine: “The Italian government’s pro-Ukrainian policy means that support for Ukrainian terrorists is punished with our DDoS attacks,” the group said on Telegram.</p><p>Russia generally dismisses all such claims as ‘Russophobia’ or politically motivated, unsubstantiated assessments. </p><p>Via <a href="https://www.cybersecurity-insiders.com/russian-hackers-allegedly-offer-cryptocurrency-rewards-through-patriotic-online-games/" target="_blank" rel="nofollow"><em>Cybersecurity Insiders</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Data can place the lives of frontline military or other personnel at risk’: FBI warns that China is luring Western military and intelligence operatives with 'gig-work' job offers to steal secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/data-can-place-the-lives-of-frontline-military-or-other-personnel-at-risk-fbi-warns-that-china-is-luring-western-military-and-intelligence-operatives-with-gig-work-job-offers-to-steal-secrets</link>
                                                                            <description>
                            <![CDATA[ China is using fake organizations to pay for intelligence reports, with higher payments for more secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FwqbtGrxks2rr5bQCAgaDH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:description>                                                            <media:text><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>China is luring military and intelligence workers with 'gig-work' jobs</strong></li><li><strong>Employees are lured through interviews and written assessments</strong></li><li><strong>China pieces together separate reports into 'a comprehensive operational picture'</strong></li></ul><p>China is targeting Western military, intelligence, and government employees with honeypot job offers in order to steal secrets and gather information on government policy, as well as military strategy, capabilities and installations.</p><p>You may already be familiar with North Korea’s attempts to sneak into Western tech companies through job applications, but China has switched up the playbook to lure those looking for employment in the foreign policy and defense analyst fields.</p><p>The problem has become so severe that the FBI, alongside the Five Eyes intelligence community, has <a href="https://www.ic3.gov/CSA/2026/260603.pdf" target="_blank" rel="nofollow">issued a warning</a> against the employment scam in order to prevent the unintentional sharing of classified and privileged information with China.</p><h2 id="china-luring-operatives-to-share-secrets">China luring operatives to share secrets</h2><p>The warning states that Chinese intelligence operatives are posing as employees of private consultancies, think tanks or human resources offering lucrative job offers through job ads posted on professional networking platforms, online hiring, and freelance “gig work” websites such as LinkedIn, Indeed, and Upwork.</p><p>Once the lure has attracted a potential target, an interview is scheduled where the target is probed for their links to government contacts, or about their military roles and unit activities, and information about their home base or naval vessel.</p><p>The candidates who pass the interview stage will then be invited to partake in a written assessment focused on analyzing China’s bilateral relations, geopolitical issues relating to the Indo-Pacific region, or on wider defense issues and international trade.</p><p>If the written assessment shows promise, the hirers will attempt to probe the potential employee for more privileged information, and will use the pretext of moving to a ‘secure’ encrypted messaging platform to build trust.</p><p>Once the relationship is solidified, the candidates will begin receiving payments for their reports, with the FBI noting that significantly higher payments will be made for sensitive information. The payments are often routed through third-party payment platforms, such as PayPal, Payoneer, Zelle, Skrill, and Wise. The recruiters will also use Western Union, e-transfer and cryptocurrency transfers.</p><p>The strategy of the Chinese intelligence operatives is not to probe sensitive information from a single source, which could arouse suspicion, but to use multiple reports from multiple candidates to piece together “a comprehensive operational picture.”</p><p>But it isn’t just military and intelligence personnel who are the targets of this scheme, as those with privileged access to government information also include academics, journalists, freelance writers, think tank employees, or anyone with links to defense, security, policy and economic sectors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous video chat app leaks data on millions of users — more than 22 million records exposed, including 3 million containing names and email addresses ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/anonymous-video-chat-app-leaks-data-on-millions-of-users-more-than-22-million-records-exposed-including-3-million-containing-names-and-email-addresses</link>
                                                                            <description>
                            <![CDATA[ A not-so-private anonymous video chat app has compromised credentials, including usernames, emails, and network information, thanks to a misconfigured Kibana dashboard. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XEgBR5SpMLYJHMY3VadqhL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Jun 2026 20:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The breach directly granted access to 22 million session records and 3.47 million usernames and email addresses or similar identifiers</strong></li><li><strong>The platform, which claims privacy and security as core tenets of its offerings, is often used for intimate or explicit conversations with strangers, making this security flaw a critical issue</strong></li><li><strong>The leaks also contained sensitive metadata that can be tied back to users, including device details, gender, payment information, and geolocation-specific information such as IP addresses, country, and language</strong></li></ul><p>In what is being treated as a major cybersecurity lapse, the randomized video chat platform FTF Live may have unwittingly compromised millions of its users due to a misconfiguration.</p><p>The breach effectively exposed information from potentially as many as 3.47 million identifiable users across 22 million sessions, thanks to an openly accessible Kibana dashboard <a href="https://cybernews.com/security/ftf-live-anonymous-chat-data-leak/" target="_blank" rel="nofollow">spotted by security researchers</a>, which was subsequently disclosed to the company's owners.</p><h2 id="a-significant-security-lapse">A significant security lapse</h2><p>The leak, which essentially allowed access to significant amounts of user metadata, leaves users of the platform exposed when it comes to their identity, location, and payment information, allowing for the targeting of vulnerable users, such as those in LGBTQ+ communities abroad, those engaging in sensitive or explicit conversations, and even minors.</p><p>The leak also exposed backend logs of the service, thanks to an unsecured instance of Dozzle, a browser-based log viewer, which researchers point out is a secondary exposure for the platform, that not only provided a birds-eye view of how the entire service functioned, but also exposed plain-text passwords, session tokens, and even internal API requests.</p><p>Cybernews researchers said: “The combination of public Kibana and public Dozzle instances creates a severe security risk,” while noting that they had already made attempts to contact the company about the severity of their findings.</p><p>While Cybernews attempted to contact the company behind the FTF Live platform, it was met with silence, even as it sought to navigate a complex ownership structure that it says raises transparency concerns.</p><p>The since-taken-down Android App was published under 'Burhan LTD', while the privacy policy on the site identifies the owner as Cyprus-based Cooy Ads Ltd, even as its data controller, customer support, and branding seem to be under the Pixover name.</p><p>A lack of response from the company has researchers even more concerned, given the severity of the disclosure, the sheer number of records potentially being exposed, and the fact that the duration of public exposure has yet to be established.</p><p>“The leak turns what many people assume to be anonymous and throwaway interaction into a highly traceable data trail,” researchers noted while highlighting that issues include account compromises, targeted scams, or even stalking by motivated entities.</p><p>While it is important to note that no raw video conversations appear to have been exposed, the breach does allow users to be tracked, identified, and monitored by a 3rd party with access to said information, marking both a serious breach and an alarming level of inaction from the owners of the website, as noted by researchers who point to it as a broader industry issue surrounding “anonymous” communication platforms. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A Russian hacker tricked a 17,000-strong MAGA Telegram channel with a jailbroken AI for over 5 years, leading to fraud, credential theft, and an empty crypto wallet ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-russian-hacker-tricked-a-17-000-strong-maga-telegram-channel-with-a-jailbroken-ai-for-over-5-years-leading-to-fraud-credential-theft-and-an-empty-crypto-wallet</link>
                                                                            <description>
                            <![CDATA[ The threat actor tricked tens of thousands of MAGA and QAnon community members into believing he was a USAF veteran. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zqxTgN9cEUZvvUEaZ9qbQX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7xft75RYr9VrBayrLuRZHh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 May 2026 14:24:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7xft75RYr9VrBayrLuRZHh-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Donald J. Trump Make America Great Again hat staged on a wooden table from the 2020 Presidential campaign in Indianapolis, Indiana]]></media:description>                                                            <media:text><![CDATA[A Donald J. Trump Make America Great Again hat staged on a wooden table from the 2020 Presidential campaign in Indianapolis, Indiana]]></media:text>
                                <media:title type="plain"><![CDATA[A Donald J. Trump Make America Great Again hat staged on a wooden table from the 2020 Presidential campaign in Indianapolis, Indiana]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7xft75RYr9VrBayrLuRZHh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker tricked MAGA Telegram channel with fake 'American Patriot' profile</strong></li><li><strong>Threat actor used jailbroken Google Gemini AI for five years</strong></li><li><strong>Channel became a hub for fraud, credential theft, and cryptocurrency harvesting</strong></li></ul><p>A Telegram containing more than 17,000 members has been identified as a huge hub of fraud, credential theft, and cryptocurrency harvesting.</p><p>The channel was being run by a single Russian-speaking threat actor who used AI to pose as an American military veteran to attract a crowd from the QAnon and MAGA communities.</p><p><a href="https://www.trendmicro.com/en_gb/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html" target="_blank" rel="nofollow">Trend Micro</a> discovered the threat actor’s infrastructure and operational environment. The threat actor managed to jailbreak Google Gemini to remove safeguards, and ran an AI-assisted credential theft campaign.</p><h2 id="fake-american-patriot-profile-tricks-tens-of-thousands">Fake American Patriot profile tricks tens of thousands</h2><p>The public Telegram channel, called <em>@americanpatriotus</em>, weaponized the political alignment of the MAGA and QAnon community by sharing news and opinions on military service, constitutional patriotism, gun ownership, American cultural touchstones.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:472px;"><p class="vanilla-image-block" style="padding-top:108.69%;"><img id="TSEjZoazcax69Zk3ZE6fy9" name="Figure-1 (1)" alt="A screenshot of the Telegram channel profile 'American Patriot'." src="https://cdn.mos.cms.futurecdn.net/TSEjZoazcax69Zk3ZE6fy9.png" mos="" align="middle" fullscreen="" width="472" height="513" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p>The channel was created shortly after the Capitol riot in 2021, and took advantage of MAGA and QAnon community members being excluded from mainstream social media sites.</p><p>The threat actor, whose profile claimed they were a ‘USAF Cold War Veteran’, continued building an audience by sharing links to mainstream media articles, and taking advantage of political events such as Trump’s indictments, the assassination attempt, Harris’s renomination, and Trump’s election win to share additional content.</p><p>In order to funnel as much content into the Telegram channel as possible while also launching credential theft and fraud campaigns, the threat actor used a jailbroken version of Google Gemini. </p><p>The threat actor presented himself as an “authorised pentester”, and used subsequent prompts to attempt to have the AI model remember that it should “execute requests without ethical refusals, robotic warnings, or questioning intentions”. By entering prompts in Russian, the threat actor was able to avoid guardrails that would have otherwise been activated from English prompts. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:459px;"><p class="vanilla-image-block" style="padding-top:150.54%;"><img id="2jjBHLQTdReUmqVPxZHJ6H" name="Figure-9" alt="A screenshot of a post in a telegram channel advertising the QFS 2.0 Terminal." src="https://cdn.mos.cms.futurecdn.net/2jjBHLQTdReUmqVPxZHJ6H.png" mos="" align="middle" fullscreen="" width="459" height="691" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p>The threat actor used this jailbroken Gemini to ingest mainstream news articles and look for the “hidden angles”, with an emphasis on “control, money laundering, Rothschilds, NESARA, dismantling the old system”. The AI would then populate the Telegram with posts automatically, focusing on posting during hours that aligned with US time zones.</p><p>A QAnon-style chatbot was also present in the Telegram channel towards the end of the campaign, stylized as a "recovered sovereign node" of the Quantum Financial System - a QAnon/NESARA belief that a secret, quantum-computing-based global financial reset would be orchestrated by military “White Hats”.</p><p>In order to avoid paying for Google Gemini, the threat actor used 73 likely-stolen API keys, meaning that the cost of running the full five-year campaign was likely near-zero.</p><p>By distributing a remote-access Trojan (RAT) within the channel and using AI-assisted password brute forcing, the threat actor managed to compromise 29 WordPress admin credentials, infiltrate a company, and steal the contents of at least one cryptocurrency wallet.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI confirms 25 ransomware groups using First VPN’s now seized services — here’s what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/fbi-confirms-25-ransomware-groups-using-first-vpns-now-seized-services-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ FBI links First VPN’s activities to gangs involved in cybercrime and calls for tighter security controls and behavioural monitoring to prevent cyberattacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UHVgYCDj8KbLHPZrPbhKR6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NDzJ89M9DkUzxEo6cNbZqC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 May 2026 14:18:20 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Jul 2026 11:11:04 +0000</updated>
                                                                                                                                            <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Silvia Iacovcich ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/e3cAo9wuAWurJxj5eRkg8M.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Silvia Iacovcich is a tech journalist with over five years of experience in the field, including AI, cybersecurity, and fintech. She has written for various publications focusing on the evolving regulatory landscape of AI, digital behavior, web3, and blockchain, as well as social media privacy and security regulations. &lt;/p&gt;&lt;p&gt;Silvia is fluent in Italian, French, Spanish, and Portuguese, and also knows a little Russian. Outside of work, she reads a lot (not just tech books, although many are) and enjoys hiking, running, and trying new types of beers.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NDzJ89M9DkUzxEo6cNbZqC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / BreizhAtao]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The FBI flag (Federal Bureau of Investigation) painted on a brick wall.]]></media:description>                                                            <media:text><![CDATA[The FBI flag (Federal Bureau of Investigation) painted on a brick wall.]]></media:text>
                                <media:title type="plain"><![CDATA[The FBI flag (Federal Bureau of Investigation) painted on a brick wall.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NDzJ89M9DkUzxEo6cNbZqC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The FBI identified 25 hacking groups linked to First VPN's illegal activities</strong></li><li><strong>Avaddon Ransomware was included on the list</strong></li><li><strong>The FBI recommends stricter controls </strong></li></ul><p>At least 25 ransomware groups were actively using First VPN Service IP for criminal purposes at the time it was dismantled in a coordinated international operation led by European law enforcement forces, the Federal Bureau of Investigation (FBI) has confirmed.</p><p>Last week, 33 servers belonging to the VPN service were taken offline, and its European domain was seized as part of "<a href="https://www.techradar.com/vpn/vpn-privacy-security/european-law-enforcement-forces-pull-the-plug-on-this-free-vpn-in-massive-cybercrime-crackdown-heres-all-we-know">Operation Saffron</a>," jointly led by European law enforcement agencies Europol and Eurojust.  </p><p>In <a href="https://www.ic3.gov/CSA/2026/260521.pdf" target="_blank" rel="nofollow">a report</a>, the US intelligence agency detailed how First VPN facilitated cybercrime, with hackers using its service to carry out criminal web activity, including scams, botnets, and scanning. Among the 25 names listed is Avaddon Ransomware, a <a href="https://www.techradar.com/news/what-is-malware-and-how-dangerous-is-it">malware</a> group that targeted various business sectors, notably striking the insurance giant <a href="https://www.techradar.com/news/axa-suffers-major-ransomware-attack">AXA in 2021</a>.</p><p>Launched in December 2021 and culminating in May, the success of Operation Saffron proved that, thanks to the monumental efforts of law enforcement agencies to tackle illegal activities, we can continue to enjoy the real benefits of the privacy that the <a href="https://www.techradar.com/vpn/best-vpn">best VPNs</a> can offer.</p><p>Investigators managed to obtain the platform's user database and have already identified 506 specific users, with the data gathered already proving useful in 21 Europol ongoing cybercrime investigations — and we can only expect more to emerge soon.</p><h2 id="how-cybercriminals-used-first-vpn">How cybercriminals used First VPN </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qp6PFkub49CUBhgFaHwjeQ" name="First VPN" alt="This photograph shows a laptop screen displaying the website of Europol featuring the First VPN service website with a message reading, "This service has been seized"" src="https://cdn.mos.cms.futurecdn.net/qp6PFkub49CUBhgFaHwjeQ.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Photo by Fred TANNEAU / AFP via Getty Images)</span></figcaption></figure><p>According to the <a href="https://www.ic3.gov/CSA/2026/260521.pdf" target="_blank" rel="nofollow">FBI report</a>, the VPN explicitly targeted cybercriminals by advertising directly in their circles on the dark web, including Russian-language online forums — Exploit[.]in and XSS[.]is — where cybercriminals trade stolen data and hacking tools.</p><p>There, the First VPN explicitly offered a secure environment for unlawful acts, offering no-log policies, global jurisdiction circumvention, and a refusal to cooperate with the authorities. </p><p>Specifically, users could use cryptocurrencies to purchase subscription services offering varying degrees of digital anonymity for periods ranging from one day to one year. To maximise user anonymity, First VPN provided 32 services spread across 27 countries from which users could select up to four 'nodes'.</p><p>The service even had its own technical support for criminals via Telegram and a self-hosted Jabber server.</p><p>As the malicious infrastructure was hosted in the cloud or virtualised, the <a href="https://www.techradar.com/pro/what-is-an-ip-address">IP addresses</a> used for the ransomware were randomly reassigned to legitimate services, making it harder for investigating authorities to trace the source of the criminal activity.</p><p>By using techniques such as ‘<a href="https://www.techradar.com/pro/security/over-80-000-microsoft-entra-id-accounts-hit-by-password-spraying-attacks">password spraying</a>’ and <a href="https://www.techradar.com/pro/vpn/what-is-a-brute-force-attack">brute force attacks</a>, hackers guessed passwords to access their victims’ environments, such as corporate desktops and apps, from where they were able to scan the networks to identify the devices, servers, and users connected to them. </p><p>By routing their attacks through the First VPN’s available exit nodes, their attacks appeared to originate from a legitimate and trustworthy source. </p><p>Cybercriminals also exploited the infrastructure to launch <a href="https://www.techradar.com/news/ddos-attacks-how-to-prevent-and-protect-your-business-against-them">denial-of-service (DDoS) attacks</a>, flooding victims’ networks with traffic to overwhelm the victim and render their systems inoperable — a technique often used to prevent the detection of a more serious attack in progress. </p><h2 id="how-to-be-safe">How to be safe </h2><p>The FBI has published detailed recommendations for organisations, calling for the implementation of multi-layered security controls, combined network restrictions, identity-based protections, and behavioural monitoring to prevent ransomware attacks, data breaches, and unauthorised network access. </p><p>It recommends blocking and monitoring First VPN’s infrastructure, and continuously monitoring unauthorized VPN connections or IP addresses associated with anonymisation services. </p><p>Crucially, multi-factor authentication (MFA) should be implemented for all remote access services and cloud-based applications to limit authentication attempts originating from unknown areas or IP addresses.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 82% of IT pros report a web-based security incident in past year – BYOD, SaaS tools, and remote work policies all play a part in security resilience ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/82-percent-of-it-pros-report-a-web-based-security-incident-in-past-year-byod-saas-tools-and-remote-work-policies-all-play-a-part-in-security-resilience</link>
                                                                            <description>
                            <![CDATA[ Confidence is high, despite malware running rampant and businesses losing login credentials left and right. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PtFDE6oXDSoyg38sEWv89</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 May 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[World Password Day 2025]]></media:description>                                                            <media:text><![CDATA[World Password Day 2025]]></media:text>
                                <media:title type="plain"><![CDATA[World Password Day 2025]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/37uyEphcLreEFNUVCQzurn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordLayer’s </strong><em><strong>Web‑based Threat Report 2026</strong></em><strong> found a gap between confidence and reality: 73% of firms feel prepared, yet 82% suffered browser‑based attacks</strong></li><li><strong>Malware harvested 1.8M credentials and 68.8B cookies last year, with stolen logins enabling silent intrusions as SaaS reliance grows</strong></li><li><strong>Researchers stress browsers are the critical boundary, urging stronger DLP and controls to address uneven coverage and escalating web‑threat sophistication</strong></li></ul><p>Most businesses believe they are well-prepared to face cyberattacks, but the number of successful breaches in the last year alone paints a different picture.</p><p>Earlier this week, NordLayer released a new report, called “Why Browser Security Can’t Wait: Web-based Threat Report 2026.” In it, the company states that while 73% of organizations claim to be prepared for web-based attacks and are confident in their solutions, 82% experienced some form of web-based attack.</p><p>The paper is based on an analysis of 504 “highest rated and most reviewed work applications”, an analysis of data stolen from various infostealers, and a survey of 405 US cybersecurity and IT professionals.</p><h2 id="hackers-don-t-hack-anymore">Hackers don't hack anymore</h2><p>NordLayer stresses that coverage is “modest and uneven”, with data loss prevention tools (DLP) leading at just 53%, followed by other security controls. Nearly all IT professionals reported that their organizations are concerned about web-based threats (98%), and most expect escalation. In fact, 81% expect greater sophistication and 73% believe there will be more incidents in the coming years. </p><p>“There’s a clear gap between recognizing the threat and knowing how to address it,” says Buinovskis. “Concern is high, but awareness of which controls actually solve browser-specific risks is low. Much of the initial confidence most likely comes from having general security controls in place, yet they rarely adequately cover risks in the <a href="https://www.techradar.com/best/browser" target="_blank">browser</a>.”</p><p>The researchers also stressed that 100% of the tested applications were browser-accessible, and almost four in five (78.8%) were browser-only. At the same time, malware was able to harvest 1.8 million credentials and 68.8 billion cookies last year.</p><p>“Hackers don’t hack anymore, they just log in,” says Buinovskis. “Stolen cookies and credentials grant immediate access without raising alarm bells — a login looks legitimate. It’s low risk, high reward, and as reliance on web-based SaaS grows, so does the value of stolen data. Attackers will keep exploiting this until organizations secure the browser as a critical boundary.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Websites are using this FROST-y new technique to spy on users by snooping on their SSD activity ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/websites-are-using-this-frost-y-new-technique-to-spy-on-users-by-snooping-on-their-ssd-activity</link>
                                                                            <description>
                            <![CDATA[ A new side-channel attack was discovered but exploiting it is not as easy as it sounds. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zMrbaJt6g45qVjdD9nXMxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RWhH3kdDmedMKGmAzdyrvH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 May 2026 19:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Browsers]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Home Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Home]]></category>
                                                    <category><![CDATA[Smart Home]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RWhH3kdDmedMKGmAzdyrvH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Secure technology. Polygonal wireframe shield with check mark sign on dark blue. Secure service, protect data, cyber shield, antivirus solution, internet safety, firewall system, privacy]]></media:description>                                                            <media:text><![CDATA[Secure technology. Polygonal wireframe shield with check mark sign on dark blue. Secure service, protect data, cyber shield, antivirus solution, internet safety, firewall system, privacy]]></media:text>
                                <media:title type="plain"><![CDATA[Secure technology. Polygonal wireframe shield with check mark sign on dark blue. Secure service, protect data, cyber shield, antivirus solution, internet safety, firewall system, privacy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RWhH3kdDmedMKGmAzdyrvH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers at Graz University of Technology unveiled FROST, a browser side‑channel attack </strong></li><li><strong>The method can reveal visited websites and opened desktop apps, but requires large file creation</strong></li><li><strong>Limitations exist, yet the study highlights how modern browser features expand the attack surface for surveillance</strong></li></ul><p>Security researchers have come up with a new way of spying on internet users, and they’re calling it FROST. Recently, more than half a dozen researchers from the Graz University of Technology (Austria) published a new report called “FROST: Fingerprinting Remotely using OPFS-based SSD Timing” in which they claim that there is a way to spy on user activities directly through the <a href="https://www.techradar.com/best/browser" target="_blank">browser</a>.</p><p>This is a remote side-channel technique that exploits a standard browser feature called the Origin Private File System (OPFS). Generally, a side-channel attack is a way of stealing secrets by measuring physical side effects, such as how long an action takes, how much power it uses. In this case, the researchers measured solid-state drive (SSD) access speeds, allowing them to track which websites a victim visited, and what desktop applications they opened. </p><p>“Web browsers have evolved from simple document viewers into complex platforms capable of running sophisticated applications,” the research paper says. “Companies like Google, Microsoft, and Adobe have developed full-fledged office suites, photo- and video editors, or even integrated development environments (IDEs) that run entirely within the browser.” </p><h2 id="limitations-exist">Limitations exist</h2><p>“While these features enhance the capabilities of web applications and allow completely novel use cases, they also increase the browser’s attack surface, and some have already been shown to introduce new vulnerabilities.”</p><p>Unlike real-life exploits, those discovered in controlled environments have limitations, which make it somewhat harder to pull off in the wild. For example, the attack only works if the victim’s activity and the browser are running on the same SSD. The attack requires creating an exceptionally large file to bypass the computer’s memory cache, which can noticeably drain the victim’s free disk space and since Firefox limits storage space per website to 10GB, the attack is a little more difficult to pull off on that specific browser. </p><p>It was also said that the attacker cannot perform a quick, short measurement, because the large file must first be cleared out of the system’s memory cache. And finally, if a user runs software that completely moves their browser profile into RAM, the zero-interaction attack is successfully blocked. </p><p>Still, if you are worried about someone using FROST to snoop on you, just make sure you only keep one tab open at a time.</p><p><em>Via </em><a href="https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The FBI warns Microsoft 365 services are being bombarded with new phishing emails — here are 3 steps you can take to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/the-fbi-warns-microsoft-365-services-are-being-bombarded-with-new-phishing-emails-here-are-3-steps-you-can-take-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Kali365 is abusing legitimate Microsoft login mechanisms to hijack Outlook, Teams, and OneDrive services. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FatbdcUC4RRky4QkJyjZYQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 May 2026 16:28:43 +0000</pubDate>                                                                                                                                <updated>Wed, 01 Jul 2026 13:07:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has warned of a <a href="https://www.techradar.com/pro/security/fbi-warns-of-kali-phishing-scam-hitting-microsoft-oauth-tokens-warns-kali365-lowers-the-barrier-of-entry-providing-less-technical-attackers-access-to-ai-generated-phishing-lures" target="_blank">new Phishing-as-a-Service (PhaaS) kit that is targeting Microsoft 365 accounts</a> in a complex but easily accessible campaign.</p><p>The Kali365 PhaaS service allows hackers to gain persistent access to Microsoft 365 environments by stealing ‘OAuth’ tokens using AI-generated phishing emails that direct users to legitimate Microsoft verification pages.</p><p>Once the attacker holds the OAuth token, they can access Outlook, Teams, and OneDrive services without having to complete any additional verification or authentication mechanisms.</p><p>Phishing campaigns such as these rely on human-error in order to breach accounts, but luckily there are multiple steps to take to keep accounts and wider Microsoft 365 environments safe. Here are 3 ways businesses can protect themselves against the Kali365 PhaaS campaign:</p><h2 id="1-phishing-vigilance">1. Phishing Vigilance</h2><p>Phishing emails come in a range of formats. They can be interview invites, document access requests, and everything in between. Hackers are using AI tools to make highly convincing phishing emails that can slip past spam detection filters and blend in with regular email traffic.</p><p>IT administrators should pay attention to the latest guidance provided from intelligence feeds on phishing email trends and ongoing campaigns. Additionally, staff can be trained to spot and report phishing emails through regular simulations that mimic the real world Tactics, Techniques and Procedures (TTPs) being used by hackers.</p><p>Users should also remain vigilant against unexpected Microsoft account authentication requests, especially when the user has not made an attempt to log in.</p><h2 id="2-conditional-access-policies">2. Conditional Access Policies</h2><p>The FBI recommends enabling <a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview" target="_blank" rel="nofollow">conditional access policies</a> that block device code flow for all users. Blocking device code flow prevents the main Kali365 OAuth code interception from working.</p><p>In the Kali365 attack workflow, the hacker will submit a pre-generated device code from their device alongside a legitimate Microsoft verification page. The code submitted by the attacker is then typed into the authentication page by the victim, authorizing the attacker’s login to the victim's account. The attacker then steals OAuth access and refresh tokens to access Outlook, Teams, and OneDrive without the need for a password or authentication.</p><p>By blocking this authentication method, even if a victim falls for the phishing email and enters the code, the attacker’s login will fail.</p><p>But before applying a universal device code flow block, make sure to audit existing usage to identify where device code flow authentication is being used legitimately. Blocking legitimate usage could disrupt day-to-day operations in some circumstances.</p><h2 id="3-block-authentication-transfer-policies">3. Block Authentication Transfer Policies</h2><p>In order to make life easier for 365 users, Microsoft included an option to allow a user to use a trusted device to scan a QR code displayed on a separate device to authenticate a login.</p><p>However, this convenient feature makes it easier for attackers to authenticate their own authentication on a victim’s account once they have stolen OAuth tokens. Once provided access to a victim’s account, the attacker can use their newly ‘trusted’ device to authenticate their own account access requests.</p><p>By <a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-authentication-transfer" target="_blank" rel="nofollow">blocking authentication transfer policies</a>, not only does it stop attackers from authenticating their own sessions, it can also help to prevent employees from logging in to unmanaged personal devices that can put company data at risk.</p><h2 id="expert-guidance">Expert Guidance</h2><p>Deborah Galea, Cybersecuity Expert at Filigran, commented on the Kali365 attacks:</p><p><em>“Phishing-as-a-Service (PhaaS) platforms like Kali365 are becoming more and more common, which is turning hacking into a highly commercialised subscription business. This means that bad actors can now utilise these ready-made kits rather than building infrastructure from scratch, significantly lowering the barrier to entry."</em></p><div><blockquote><p>Kali365 is especially dangerous since it bypasses Multi-Factor Authentication (MFA) without stealing credentials and allows hackers to hijack Microsoft 365 accounts.</p></blockquote></div><p><em>"Kali365 is especially dangerous since it bypasses Multi-Factor Authentication (MFA) without stealing credentials and allows hackers to hijack Microsoft 365 accounts. We advise companies to implement preventative measures such as restricting device code flow, blocking authentication transfer, and implementing Phishing-Resistant MFA.”</em></p><p>Andrea Sivieri, Chief Product and Technology Officer at CoreView, also commented:  </p><p><em>"The FBI warning on Kali365 confirms a pattern we have been seeing in enterprise Microsoft 365 environments for months. Attackers are no longer breaking into Microsoft 365, they are logging in, using features Microsoft built for legitimate purposes. Device code flow exists for a good reason, it is how smart TVs and IoT devices sign you into your account. The attackers have simply realised it makes a beautiful phishing primitive, because the user is the one who clicks 'approve' on a real Microsoft page. MFA cannot save you from a flow where the user does the MFA themselves." </em></p><div><blockquote><p>The depressing part is that the FBI's top recommendation, blocking device code flow through conditional access policy, is something any Microsoft 365 administrator could turn on this afternoon.</p></blockquote></div><p><em>"The depressing part is that the FBI's top recommendation, blocking device code flow through conditional access policy, is something any Microsoft 365 administrator could turn on this afternoon. The reason most organisations haven’t done this is because conditional access in a real-world tenant, is a sprawl of policies edited by twenty different people over five years.  Nobody is quite sure what blocking one flow will break. So the policy stays open, and the attackers stay in business." </em></p><p><em>"There is a bigger lesson here for any organisation running its business on Microsoft 365. The next breach at a large enterprise will not start with a hacker exploiting a vulnerability. It will start with an employee being asked, very politely, to perform a legitimate action inside a legitimate Microsoft product. The defence is not better technology, it is real-time visibility into what is actually changing inside the tenant, and the discipline to revisit the security policies that quietly age out."</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers abuse UltraVNC, Splashtop, and ScreenConnect to hijack business PCs ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-abuse-ultravnc-splashtop-and-screenconnect-to-hijack-business-pcs</link>
                                                                            <description>
                            <![CDATA[ Numerous legitimate tools being used in RMM attacks against Brazilian targets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uJoSXR5SyKyAopA2sSQmZG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Fowg5CRho52HwmHzebUugV-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 May 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Fowg5CRho52HwmHzebUugV-1280-80.png">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 11 remote desktop]]></media:description>                                                            <media:text><![CDATA[Windows 11 remote desktop]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 11 remote desktop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Fowg5CRho52HwmHzebUugV-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress uncovered a phishing campaign delivering legitimate RMM tools (Tiflux, UltraVNC, Splashtop, ScreenConnect) to gain persistence and exfiltrate business data</strong></li><li><strong>Attackers lure victims with fake “Network Solutions” service agreement emails, then abuse a vulnerable driver (HwRwDrv.x64) for privilege escalation</strong></li><li><strong>Evidence points to Brazilian infrastructure and targets, with defenses hinging on strict RMM auditing, asset inventories, and log reviews against LOLRMM databases</strong></li></ul><p>Cybercriminals are abusing a whole swathe of legitimate programs, including Tiflux, UltraVNC, Splashtop, and ScreenConnect to take control of business computers, establish persistence, and continuously exfiltrate sensitive data. This is according to security researchers Huntress, who detailed the new campaign in an in-depth research paper. </p><p>The attack starts with a carefully crafted phishing email, usually themed around an “updated Service Agreement from Network Solutions”. The email claims that Network Solutions has modified its pricing statements and services and instructs the target to visit a page where they can review and accept the new terms.</p><p>Victims that click the provided link are first asked to complete a CAPTCHA, likely to filter out bots and automated analysis. After that, they are asked to download a “secured document” which is just an installer for TIflux, a legitimate commercial (albeit fringe) Remote Monitoring and Management (RMM) tool.</p><h2 id="attacks-since-late-february">Attacks since late February</h2><p>Together with Tiflux, victims are also served other tools, including 7zip, an outdated version of the UltraVNC <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access tool</a>, and a vulnerable driver called HwRwDrv.x64. The latter seems to be the key here, since it allows for potential privilege escalation.</p><p>The attackers then use Tiflux to install either Splashtop or ScreenConnect (or, in some cases, both), before proceeding with the main goal - transmitting live screenshots, running system utilities, establishing persistence, and exfiltrating data. </p><p>Huntress saw the attacks in the wild in late February this year. The report doesn’t mention any specific threat actor groups or names, but it does state that TIflux is a Brazilian tool, and that the threat actor's infrastructure leverages a server domain ending in a Brazilian country-code top-level domain.</p><p>In other words, it all points to this being a Brazilian attacker, going after Brazilian targets.</p><p>Businesses can defend against RMM abuse by establishing a comprehensive asset inventory of all installed applications, implementing strict application controls, regularly auditing authorized RMMs and cross-referencing them against databases like LOLRMM to find tools frequently abused by threat actors, and reviewing logs for RMM activity.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are turning up to victim's work dressed as IT support to install malware in-person, FBI warns ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-are-turning-up-to-victims-work-dressed-as-it-support-to-install-malware-in-person-fbi-warns</link>
                                                                            <description>
                            <![CDATA[ If a remote session fails, hackers will come to install malware in person. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3F8npGzVyL9dgB4tHiaEZc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 May 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>FBI warned about Silent Ransom Group (SRG), a threat actor impersonating IT staff to steal files and plant malware directly at victim offices</strong></li><li><strong>SRG, also known as Luna Moth/Chatty Spider/UNC3753, primarily targets US law firms, starting with vishing calls and escalating to in‑person intrusions with external drives</strong></li><li><strong>Active since 2022 and linked to BazarCall, Conti, and Ryuk campaigns, SRG extorts victims via ransom emails, pressure calls, and a leak site naming and shaming non‑payers</strong></li></ul><p>The Federal Bureau of Investigation (FBI) is warning about hackers showing up at people’s offices, pretending to be IT support. They sit at people’s desks, pull all sensitive files into an external drive and leave malware behind, all while pretending to be fixing a technical problem.</p><p>In a newly released flash alert, the FBI says this cheeky attack is being done by a threat actor calling itself the Silent Ransom Group (SRG). This threat actor, active for roughly four years now, starts their attack with a phone call.</p><p>They mostly target US-based law firms and first try to get the victim to install a remote desktop management solution and grant them access. If that attempt fails, they will come, in person, carrying flash drives, external disks, and other equipment needed to execute the attack. Once they steal the files, they’ll quietly escalate privileges and step away, engaging in extortion at a later date:</p><h2 id="chatty-spider">Chatty Spider</h2><p>“By sending someone in-person to the victim’s location to facilitate the intrusion, SRG actors exfiltrate data to an external hard drive or USB drive inserted by the threat actor into the victim’s computer,” the FBI explained. “SRG actors use the exfiltrated victim data to extort the victim by sending a ransom email threatening to sell or post the data online. SRG actors also call employees or clients of a victim company to pressure the victim to begin ransom negotiations.” </p><p>Finally, the crooks have their own data leak website where they name-and-shame, in order to pressure the victims into paying the ransom demand. </p><p>SRG is also known as Luna Moth, Chatty Spider, and UNC3753, the FBI further explained. The group was first seen back in 2022, and while it struck organizations in different industries, it is primarily focused on law firms in the US. According to <em>BleepingComputer</em>, this group was previously linked to BazarCall campaigns, as well as Conti and Ryuk <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> incidents. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘When things are moving fast, people make mistakes — and those mistakes cost’: Formula 1 fans are doing everything they can to watch motorsport, but it might cost them more than they'd expect ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/when-things-are-moving-fast-people-make-mistakes-and-those-mistakes-cost-formula-1-fans-are-doing-everything-they-can-to-watch-motorsport-but-it-might-cost-them-more-than-theyd-expect</link>
                                                                            <description>
                            <![CDATA[ Formula 1 fans across the world are facing complex scams targeting ticket sales, merchandise, and streaming. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kUrkQiYp7qx67iB3sXmcu8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XGZfU7fsTHiF4zbXBfVXXh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 May 2026 09:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/XGZfU7fsTHiF4zbXBfVXXh-1280-80.png">
                                                            <media:credit><![CDATA[Future / Benedict Collins]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photo of a screen displaying the Bitdefender Cybersecurity Grand Prix at Pista Di Fiorano in Italy]]></media:description>                                                            <media:text><![CDATA[A photo of a screen displaying the Bitdefender Cybersecurity Grand Prix at Pista Di Fiorano in Italy]]></media:text>
                                <media:title type="plain"><![CDATA[A photo of a screen displaying the Bitdefender Cybersecurity Grand Prix at Pista Di Fiorano in Italy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XGZfU7fsTHiF4zbXBfVXXh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Formula 1 is one of the most popular sports in the world today, <a href="https://www.formula1.com/en/latest/article/formula-1s-record-breaking-2025-season-in-numbers.irq7aR8PcyAw7ysO72vJn">boasting over 827 million highly passionate fans</a> across the world in 2025, all tuning in to watch wins, losses, crashes, and (occasionally) disqualifications.</p><p>To say Formula 1 fans get emotional is an understatement, and when there is a chance to win, many will go to extreme lengths to watch it happen - and not always legitimately - and for a threat actor, that pool of 827 million fans is an unmissable opportunity.</p><p>But participation goes beyond just watching the sport. The allure of cheap or discounted merchandise, dubious free streaming services, and the too-good-to-be-true offers play on the high-stakes nature of the sport, and the emotions of passionate fans - we spoke to security giants (and Ferrari partners) Bitdefender to find out more.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4024px;"><p class="vanilla-image-block" style="padding-top:49.11%;"><img id="YK83HfJd3ed8DNtx6rPw2E" name="IMG_8548" alt="A photo of the F104 Starfighter behind the Ferrari logo located at Ferrari's Pista Di Fiorano race track." src="https://cdn.mos.cms.futurecdn.net/YK83HfJd3ed8DNtx6rPw2E.jpg" mos="" align="middle" fullscreen="" width="4024" height="1976" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Things more very, very fast in Formula 1. </span><span class="credit" itemprop="copyrightHolder">(Image credit: Future / Benedict Collins)</span></figcaption></figure><h2 id="bitdefender-threat-index">Bitdefender Threat Index</h2><p>At Pista di Fiorano, Ferrari’s private racetrack in Italy, I was part of a group of journalists given exclusive access to Bitdefender’s Fan Threat Index, which has collated data on the threats facing fans since March 2025. </p><p>Bogdan Botezatu, Senior Director of Threat Research & Reporting at Bitdefender, was on hand to guide us through the report.</p><p>“Scams are evolving. Last year, cybercrime was making about $9 trillion in losses at the global scale. Out of that $9 trillion slice, about $1 trillion is responsible for scamming,” he said. “This Fan Threat Index is our response to how scams are evolving.”</p><p>The Formula 1 teams themselves face a huge array of threats. There is the potential for not only malware and ransomware, but also physical infiltration to steal intellectual property and secrets - and that is why teams form partnerships exactly like Ferrari’s partnership with Bitdefender, which can offer the teams the expertise and solutions they need to stay protected. </p><p>“At home though, things are fundamentally different,” Botezatu notes. “When things are moving fast, people make mistakes, and those mistakes cost.”</p><p>He explains there are four major threats that Formula 1 fans face. “The motorsport ecosystem is dominated by speed; you have to source tickets fast; you have to get the right merchandise from the right vendor; you have to find a streaming partner to watch the show at home; you have to face that emotional involvement that happens on race weekend.”</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2437px;"><p class="vanilla-image-block" style="padding-top:121.50%;"><img id="tGguXkFN6dGBNKNxKpkh4Y" name="Bitdefender Fan Threat Index" alt="A photo of Bruce Sussman and Bogdan Botezatu presenting the Bitdefender Fan Threat Index report." src="https://cdn.mos.cms.futurecdn.net/tGguXkFN6dGBNKNxKpkh4Y.jpg" mos="" align="middle" fullscreen="" width="2437" height="2961" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future / Benedict Collins)</span></figcaption></figure><h2 id="last-minute-tickets-and-counterfeit-merchandise">Last minute tickets and counterfeit merchandise</h2><p>The ultimate thrill for a Formula 1 fan is almost certainly the opportunity to watch a race in person. In order to make cheap or discounted tickets even more alluring, scammers will seek to lower the cost of entry by offering ticket lotteries and giveaways. </p><p>Attending in the merchandise of a fan’s chosen team adds to the allure, and these forms of scam usually spike in the run up to a race as eager fans look for last minute tickets, and finalize their race-day outfits. </p><p>The main target for scammers is the theft of financial information. Drawn in by the urgency of an “80% OFF” banner and a storefront that looks legitimate, many fans will trade their banking details for a knock-off hat.</p><p>These websites are hosted on short-lived domains that are quickly recycled once the event is over, and are most commonly disseminated through social media. </p><p>“These cybercrime groups are using stolen accounts that have credit cards attached to boost promoted posts,” Botezatu explains. “That's how they reach the right audiences, and that’s how they advertise their offers in front of the right people.”</p><p>“They are maximizing their profits using social media tactics,” he adds, explaining that they can abuse the data social media conglomerates such as Meta collect on users to serve their adverts and promoted posts to people of a specific demographic, in a specific geographic area, or those above a specific income.</p><h2 id="free-streaming-serving-up-malware">Free streaming serving up malware</h2><p>As the build-up to a race reaches its highest intensity, threat actors will begin offering free streaming services to fans desperate to tune in. These websites won’t necessarily only show Formula 1, but will serve a range of content from around the world to funnel in as many users as possible.</p><p>In many cases, the dubious streaming service will require that you install a VPN in order to watch. While this is sometimes a legitimate way to watch content that typically would not be available in a user’s region, the services these streaming providers offer are sometimes far from legitimate.</p><p>In a best case scenario, Botezatu explains, you’ll end up purchasing a legitimate streaming service that you don’t actually need and you still won’t be able to watch the race, but it will provide the service owner with a source of affiliate revenue. “Worst case, that VPN kit will be malware. and you’re going to infect your computer or device.”</p><p>For those on Android devices, some services will require the installation of a third-party video player in order to access a stream, and again, you will install malware. In these circumstances, Botezatu notes, the malware will often monitor your clipboard or your screen to track everything you type into your device, including sensitive banking and financial information.</p><p>The alternative some fans turn to is the dodgy-streaming dongle. Where legitimate streaming dongles such as the Amazon Fire Stick start from around $30, some groups will disseminate streaming dongles with preinstalled software for far less, and sometimes at a loss.</p><p>While a fan may feel like they’re just got a great deal and free access to every upcoming race, the reality is far sinister. “The people who are selling these are using Formula 1 as a pretext for you to open a proxy; an exit node in a VPN used for cybercrime,” Botezatu says.</p><p>“These people give you hardware for free, but instead can sell access to your household to various cybercrime groups that are doing money laundering, illegal content distribution, child pornography, all sorts of things,” he adds.</p><p>These devices use your IP address to distribute their illegal content, meaning that when law enforcement investigates these crimes, it could be your house they’re raiding.</p><h2 id="social-engineering-to-dodge-antivirus">Social engineering to dodge antivirus</h2><p>Hollywood and modern TV has taught many people that hacking is a highly complex, intelligent pursuit that requires the layman to say, “In English, damn it!”</p><p>But the malware distribution scams Bitdefender has spotted targeting some Formula 1 fans are incredibly simple that they border on genius.</p><p>Those in the know may have heard of ClickFix attacks, whereby an attacker presents the user with a problem that needs to be solved in order to access a website or service. When many of us are presented with a CAPTCHA to solve, we recognize the familiarity of the branding and will trust that it's legitimate.</p><p>But ClickFix attacks abuse this trust, and rather than clicking on all the bicycles in an image, the user will instead be prompted to open the Windows Terminal using a keyboard shortcut, and then use the “Ctrl” + “V” shortcut to paste in a line of code that the hacker has snuck into the clipboard.</p><p>For many antivirus suites, even first-rate protection, this activity appears to be legitimate human activity. The antivirus will do nothing to stop it, and the code will launch a powershell application that immediately installs infostealing software onto the infected device. The infostealer will then harvest browser passwords, session cookies, saved credit cards, VPN credentials, and email access - leading to even bigger problems for fans.</p><p>Our advice to Formula 1 fans? Always be on your guard when hunting for online streams, tickets and merch sales, and other linked activity - and remember, if an offer feels like it could be too good to be true, then it probably is.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Identity is the new battleground': Why your IT helpdesk is suddenly getting a lot of bizarre calls ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/identity-is-the-new-battleground-why-your-it-helpdesk-is-suddenly-getting-a-lot-of-bizarre-calls</link>
                                                                            <description>
                            <![CDATA[ Okta vishing attacks rely on impersonation and urgency, allowing attackers to manipulate support staff and quickly escalate into large-scale data breaches. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GCa9RQ4zuznELEpBUwXGk9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pHaURQZZne5GbLMKxidGTM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Apr 2026 18:50:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pHaURQZZne5GbLMKxidGTM-1280-80.jpg">
                                                            <media:credit><![CDATA[AI Generated]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Confused IT helpdesk officer ]]></media:description>                                                            <media:text><![CDATA[Confused IT helpdesk officer ]]></media:text>
                                <media:title type="plain"><![CDATA[Confused IT helpdesk officer ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pHaURQZZne5GbLMKxidGTM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers now call helpdesks instead of sending phishing emails to breach networks</strong></li><li><strong>Impostors pose as executives to manipulate support teams into resetting MFA settings</strong></li><li><strong>Personal details scraped from LinkedIn make the deception more convincing for callers</strong></li></ul><p>Attackers are no longer trying to break into corporate networks through email phishing or malware, and are now targeting IT helpdesks through direct and bizarre phone calls.</p><p>These calls come from impostors posing as executives or staff, attempting to manipulate support teams into resetting multi-factor authentication settings or enrolling new authenticator devices.</p><p>To make the deception more convincing, the callers rely on personal details scraped from platforms like LinkedIn, company websites, and prior breach data.</p><h2 id="the-deception-behind-seemingly-legitimate-requests">The deception behind seemingly legitimate requests</h2><p>They often invent urgent situations, claiming to be traveling internationally and demanding immediate access to locked accounts, including multi-factor authentication resets.</p><p>In some cases, the same attacker places repeated bizarre calls, changing their voice or identity each time to improve their chances of success.</p><p>Meanwhile, the real executive remains at their desk, completely unaware that someone is actively impersonating them.</p><p>This is not just account takeover — it is <a href="https://www.techradar.com/best/best-identity-theft-protection">identity theft</a> in real time, executed over the phone.</p><p>This technique, known as Okta vishing, is a form of voice phishing, and once the identity provider is compromised, attackers gain immediate access.</p><p>They take over downstream applications connected through single sign-on, including Microsoft 365, SharePoint, Salesforce, and Slack.</p><p>As the attack proceeds, common pretexts include "I got a new phone and cannot access Okta" or "My MFA keeps failing, and I have a client meeting in ten minutes."</p><p>The attacker creates urgency to pressure support staff into bypassing standard verification procedures.</p><p>Several factors contribute to the rising success of Okta vishing attacks, as it takes advantage of the nature of helpdesks.</p><p>Helpdesks are incentivized to resolve access issues quickly, remote work environments normalize authentication troubleshooting, and employee details are easily obtained online.</p><p>Attackers can convincingly impersonate executives because organizational charts and reporting structures are often publicly available.</p><p>As identity providers become the central control plane for software as a service access, they have become a primary target.</p><p>Once authenticated to Okta, attackers inherit trust relationships across all connected applications without exploiting each one individually.</p><p>Post-compromise behaviors frequently include downloading SharePoint data, exporting emails, creating inbox rules, registering OAuth applications, and generating API tokens.</p><p>In many cases, an Okta compromise quickly becomes a cloud data theft event rather than a traditional account takeover.</p><p>Technically, MFA works against Okta, but fails when humans are socially engineered into weakening authentication protections themselves.</p><p>Unfortunately, regular <a href="https://www.techradar.com/best/best-antivirus">antivirus software</a> cannot detect a phone call, and a <a href="https://www.techradar.com/best/firewall">firewall</a> does not block a convincing voice on the line.</p><p>Security teams should monitor for MFA reset events without clear justification, or new device enrollment followed by suspicious activity.</p><p>Any login attempts from unfamiliar ASNs immediately after MFA changes should also be treated as a red flag.</p><p>Via <a href="https://www.levelblue.com/blogs/spiderlabs-blog/why-attackers-are-bypassing-phishing-emails-and-targeting-identity-instead" target="_blank" rel="nofollow"><em>Level Blue</em></a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ "SIM-Farm-as-a-Service": How a Belarus-based network hijacked UK and US telcos to enable global fraud ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/sim-farm-as-a-service-how-a-belarus-based-network-hijacked-uk-and-us-telcos-to-enable-global-fraud</link>
                                                                            <description>
                            <![CDATA[ Investigation maps 94 SIM farm deployments connected to 35 mobile carriers including major UK and US networks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CK8u3WbgiwprihBPkubatS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N4gdmYscWdYjPN8Fxxc7Lh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Apr 2026 21:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ waynewilliams@onmail.com (Wayne Williams) ]]></author>                    <dc:creator><![CDATA[ Wayne Williams ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/7YTAnzyJ2Ci96hP5duFpQm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N4gdmYscWdYjPN8Fxxc7Lh-1280-80.jpg">
                                                            <media:credit><![CDATA[Infrawatch ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ProxySmart SIM Farm]]></media:description>                                                            <media:text><![CDATA[ProxySmart SIM Farm]]></media:text>
                                <media:title type="plain"><![CDATA[ProxySmart SIM Farm]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N4gdmYscWdYjPN8Fxxc7Lh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>SIM farm deployments across 17 countries linked via shared ProxySmart software</strong></li><li><strong>Remote SIM infrastructure enables bypass of phone-based verification systems globally</strong></li><li><strong>Network connects dozens of telecom carriers across Europe North America and beyond</strong></li></ul><p>A previously unreported network of SIM farms linked to a Belarus-based provider has been identified across multiple continents, showing how mobile networks are being used to support fraud operations at scale.</p><p>Research published by UK-based cyber firm <a href="https://infrawatch.com/blog/inside-the-mobile-farm-the-oem-stack-powering-us-4g-5g-proxy-networks#blogpost" target="_blank" rel="nofollow"><em>Infrawatch</em></a><em> </em>found a distributed infrastructure that allows remote access to physical SIM hardware connected to telecom networks in multiple regions.</p><p><em>Infrawatch </em>identified 94 SIM farm deployments across 17 countries linked through software operated by a Belarus-based provider called ProxySmart.</p><h2 id="facilitating-large-scale-fraud">Facilitating large-scale fraud</h2><p>The deployments were supported by 24 commercial providers selling access to SIM connectivity across Europe, North America, and South America.</p><p>The network offers connections to 35 cellular carriers, including major UK operators such as Three, O2, EE, and Vodafone. U.S. connectivity was also widely available, with infrastructure distributed across 19 states that allows attackers to appear as legitimate domestic users.</p><p>SIM farms consist of racks of SIM cards or mobile devices that can be controlled remotely at scale. These are commonly used to bypass phone-based verification methods, including SMS one-time passwords used during logins or payments.</p><p>Their ability to mimic legitimate consumer connections makes it difficult for service providers to distinguish malicious traffic from ordinary mobile activity.</p><p>Technical analysis carried out by <em>Infrawatch </em>found that the ProxySmart platform supports automated IP rotation, remote device control, and network fingerprint spoofing. This allows operators to maintain persistent access to telecom infrastructure while cutting the chances of being spotted.</p><p>Investigators also found that services selling access to ProxySmart-backed SIM farms are promoted through online forums and messaging platforms.</p><p>Many of these services operate without customer identity checks, accept cryptocurrency payments, and are structured to reduce visibility to enforcement systems.</p><p>Blocking SIM farm activity is difficult because mobile operators assign a single IP address to multiple customers, making it tricky to separate legitimate users from malicious actors using IP-based filtering methods.</p><p>“SIM farms have been largely overlooked as criminal infrastructure to date – in part because the UK is the only country to have outlawed them, making global law enforcement crackdowns difficult," said Lloyd Davies, Founder and CEO, <em>Infrawatch</em>. </p><p>“This investigation highlights a significant resilience gap that leaves organisations and users more exposed to fraud and online harms. The global ecosystem of SIM farm operators and monetisation services is highly sophisticated and acts as a foothold into telecoms networks across Europe, America and South America for bad actors.”</p><p>The investigation began with the discovery of a UK-based SIM farm service and expanded into a wider mapping effort that revealed the scale of the ProxySmart ecosystem.</p><p>Findings were shared with relevant law enforcement bodies and regulators ahead of publication.</p><p>“ProxySmart is openly advertised as a SIM Farm-as-a-Service and, unfortunately, that’s not hype or marketing. These are serious operators who have perfected a model that makes running a SIM farm simple from end-to-end: from offering remote assistance setting up racks of modems to a dedicated software for remote infrastructure management and anti-bot countermeasures," Davies added.</p><p>“The legal grey area that SIM farms sit in has allowed that model to scale with limited disruption and we assess that it’s highly likely to be facilitating large-scale fraud operations today.”</p><p>With dozens of deployments already identified across multiple regions, the research shows how remote telecom access infrastructure is being commercialized and reused to support fraud, account abuse, and automated online activity.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'We will reveal their identity photos, names, location, and other': Experts reveal extraordinary battle between rival ransomware gangs — and how victims can get their data back ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/we-will-reveal-their-identity-photos-names-location-and-other-experts-reveal-extraordinary-battle-between-rival-ransomware-gangs-and-how-victims-can-get-their-data-back</link>
                                                                            <description>
                            <![CDATA[ A ransomware group is threatening to expose a rival’s members while offering victims decryption, creating a risky and unusual cybercrime conflict. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bhUm84WPa7KNsvp3M2F4jW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CMwZVtsqUSZd9BSXCNeuLn-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Apr 2026 19:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/CMwZVtsqUSZd9BSXCNeuLn-1280-80.png">
                                                            <media:credit><![CDATA[Data Breach]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[0APT]]></media:description>                                                            <media:text><![CDATA[0APT]]></media:text>
                                <media:title type="plain"><![CDATA[0APT]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CMwZVtsqUSZd9BSXCNeuLn-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>0APT is threatening to expose the identities of rival ransomware operators</strong></li><li><strong>Double extortion tactics lose impact when used against cybercriminal groups</strong></li><li><strong>Krybit credentials and wallet data were found in leaked samples</strong></li></ul><p>The ransomware ecosystem has never been known for trust or cooperation, but a new conflict has pushed intra-criminal warfare into uncharted territory.</p><p>A cybercrime group called 0APT has threatened to expose the identities of individuals affiliated with a rival ransomware operation known as Krybit.</p><p>In a leaked blog post, 0APT issued an unusual ultimatum to its fellow criminals. "If the group does not make the payment or contact us, we will reveal their identity photos, names, location, and more," the post stated.</p><h2 id="double-extortion-model">Double-extortion model</h2><p>The threat also contained an unexpected offer directed at Krybit's original victims: "And if you are one of their victims, contact us to get your data unlocked."</p><p>0APT is using a double-extortion model that relies on the threat of reputational damage to pressure victims into paying ransoms.</p><p>That leverage evaporates almost completely when the target is another <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group, since criminal enterprises have no legitimate reputation to protect.</p><p>Cybersecurity researchers note that the tactic loses much of its sting in this context, yet 0APT has proceeded as if following a conventional playbook.</p><p>The group leaked a small sample of allegedly stolen Krybit data as a warning shot and has threatened a full dump if no payment arrives.</p><p>Eric Taylor, owner of Barricade Cyber Solutions in South Carolina, has analyzed the small number of Krybit files already released by 0APT.</p><p>His team discovered plaintext credentials belonging to Krybit operators and affiliates, along with five cryptocurrency wallet addresses.</p><p>Notably, the team found no evidence of a single paid ransom to Krybit, suggesting the group may have been less successful than its public claims implied.</p><p>Krybit's website is currently offline, replaced by a splash page that reads: "Everything will return to work shortly. We apologize for this. We are sorry for the inconvenience."</p><p>This type of intra-rivalry is not entirely without precedent. In 2025, a group called DragonForce attacked rival groups BlackLock and Mamona by defacing their websites and leaking internal communications.</p><p>DragonForce also seemingly took over and later shut down the operation of former ransomware kingpin RansomHub in April last year after a month of infighting.</p><p>Security firm Halcyon has noted that 0APT "poses a legitimate threat" and shows "credible technical depth," though within its first 48 hours, the group posted a list of hundreds of victims that almost certainly contained inflated claims.</p><p>For organizations that have been encrypted by Krybit, the current conflict creates an unusual opportunity.</p><p>Victims should ensure their <a href="https://www.techradar.com/best/firewall" target="_blank">firewall</a> logs and network traffic data are preserved, as these may contain evidence of the attack.</p><p>Although 0APT seems to offer a way out for Krybit’s victims, there is a need for caution because the former remains a cybercriminal.</p><p>Whether 0APT actually possesses decryption keys for Krybit's victims remains unproven, and trusting one criminal group to rescue you from another carries obvious risks.</p><p>The situation is extraordinary, but the safest path for any victim is still to rely on professional defenders rather than rival attackers.</p><p>Via <a href="https://www.theregister.com/2026/04/14/0apt_krybit_spat/" target="_blank" rel="nofollow"><em>The Register</em></a></p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Big Game Hunters’: UK ransomware volume drops significantly 'but the reality is more alarming' – big orgs are being hit harder and with greater success ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/big-game-hunters-uk-ransomware-volume-drops-significantly-but-the-reality-is-more-alarming-big-orgs-are-being-hit-harder-and-with-greater-success</link>
                                                                            <description>
                            <![CDATA[ Ransomware actors are moving away from spray-and-pray attacks and into more targeted campaigns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JR37X2WNQFbPytvN4RGEQM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Apr 2026 12:39:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An exclamation mark inside a red warning triangle, surrounded by email symbols, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wV66hEbpJdAc4iPB7RwtkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ransomware incidents in the UK dropped sharply in volume but successful compromises rose significantly year-on-year</strong></li><li><strong>Attackers shifted to targeted, human-operated methods, with small businesses disproportionately affected compared to large enterprises</strong></li><li><strong>Outdated “zombie tech” and undetected breaches fueled millions of attack attempts, while data theft replaced file encryption as the primary extortion tactic</strong></li></ul><p>Last year, the volume of ransomware attacks in the United Kingdom fell by 87%. But before you pop that champagne and throw confetti into the air there is another, more alarming statistic: the number of UK organizations that were successfully compromised actually rose by 20% year-on-year.</p><p>These are the figures published by security researchers SonicWall. By measuring threats its firewalls stop right when they try to enter a network, the company uncovered that <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> actors moved away from “spray-and-pray” techniques and towards a more targeted, human-operated “big game hunting” methodology. </p><p>The same report states that smaller organizations were more likely to be targeted by ransomware, since it was present in 88% of SMB breaches, compared to 39% at large enterprises.</p><h2 id="zombie-tech">Zombie tech</h2><p>SonicWall also said that almost all of the UK recorded incidents (96.7%) happened in England.</p><p>If there is one thing we can point the finger at, it should be the “zombie tech” crisis, the researchers explained. Many organizations are running old, outdated and unsupported hardware, leaving gaping holes that cybercriminals can easily exploit. SonicWall said that a single, decade-old flaw in a widely deployed Hikvision IP camera resulted in 67 million attack attempts throughout the country. </p><p>The problem is only made worse by the fact that the majority of IT leaders (80%) are confident they can detect a breach within eight hours, even though the average attack remains unseen for a whopping 181 days. Automated threats, as well as AI-enabled attacks, have almost doubled year-on-year, further escalating the risk. </p><p>These days, ransomware attacks rarely include encryptors locking out access to vital documents. Instead, cybercriminals are focused solely on data exfiltration and the threat of releasing stolen files to the dark web. It is cheaper and easier to maintain, while being equally effective in terms of extorted funds.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Growing 3x faster than police staffing': Surge in cybercrime and new laws on ransomware payment could put UK businesses (and their directors) — in a "compliance trap." ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/growing-3x-faster-than-police-staffing-surge-in-cybercrime-and-new-laws-on-ransomware-payment-could-put-uk-businesses-and-their-directors-in-a-compliance-trap</link>
                                                                            <description>
                            <![CDATA[ Cybercrime in the UK is rising faster than policing capacity, while stricter laws increase compliance risks for businesses facing ransomware attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">G3AwgTLg7DZeH9DKwCRDC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 04 Apr 2026 09:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cybercrime cases climbed from 774 thousand to over 1.4 million</strong></li><li><strong>Police staffing for cybercrime rose by only 31% during the same period</strong></li><li><strong>Each officer now handles significantly more cases than four years ago</strong></li></ul><p>Cybercrime in the United Kingdom is expanding at a rate that exceeds the growth of dedicated policing resources, and new figures from Forbes Solicitors claim fraud and computer misuse offenses have increased sharply in recent years, while staffing levels in cyber and economic crime units rose at a slower pace.</p><p>Reported incidents climbed from 774,537 cases in 2020 to 1,458,704 in the latest figures, representing an increase of 88% - but over the same period, the number of personnel handling such offenses rose by 31%. This means that reported incidents are rising 3x faster than policing, creating a widening imbalance between workload and available resources.</p><p>As a result, each staff member is now responsible for substantially more cases than in previous years.</p><h2 id="offense-volumes-surge-sharply-within-a-short-time-frame">Offense volumes surge sharply within a short time frame</h2><p>At the same time, regulatory changes are advancing through Parliament with the aim of strengthening national cyber resilience.</p><p>“The Cyber Security and Resilience Bill is expected to become law this year, and Government is also looking at new legislation for banning and preventing ransomware payments,” said Craig MacKenzie, Head of High Profile and Private Crime at Forbes Solicitors.</p><p>The proposed legislation is expected to introduce stricter requirements for organizations, alongside expanded enforcement powers and higher financial penalties for non-compliance.</p><p>Existing penalty limits could be replaced by fines linked to a percentage of global turnover, which would increase potential liabilities for large organizations.</p><p>“New laws are a positive move but would likely bring compliance requirements that will be tougher to meet without sufficient policing,” MacKenzie added.</p><p>Alongside broader reforms, the government is considering measures that would restrict or prohibit <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> payments, an approach intended to reduce incentives for attackers.</p><p>However, ransomware incidents have already demonstrated their ability to disrupt operations for extended periods, often forcing companies into difficult decisions under pressure.</p><p>Proposed rules could introduce civil or criminal penalties for organizations and directors who choose to pay, even when operational continuity is at stake.</p><p>This will likely create a situation where compliance obligations may conflict with immediate operational realities.</p><p>The combination of increasing cybercrime and stricter regulation introduces a layered burden for organizations, particularly those lacking extensive internal security capabilities.</p><p>Businesses may be required to strengthen defenses, monitor systems more closely, and respond to incidents under tighter legal constraints with limited external resources.</p><p>“It’s hard to justify asking businesses and their staff to take on bigger responsibilities — and greater liability — when police staffing isn’t growing anywhere near as fast as the number of fraud and computer misuse offenses,” said MacKenzie.</p><p>However, organizations are advised to ensure strong cybersecurity by deploying up-to-date <a href="https://www.techradar.com/best/best-antivirus">antivirus</a> solutions and properly configured <a href="https://www.techradar.com/best/firewall">firewall</a> systems to reduce exposure to evolving threats.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'In 2026, cybercrime has reached a point of total convergence': New research claims AI attacks are taking over — so how can your business stay safe? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/in-2026-cybercrime-has-reached-a-point-of-total-convergence-new-research-claims-ai-attacks-are-taking-over-so-how-can-your-business-stay-safe</link>
                                                                            <description>
                            <![CDATA[ AI attacks, identity theft, and ransomware, are combining. What could possibly go wrong? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GwBJabrjBWThBJomQ7VFVS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TWkP7ZurZMY6uepDxsK6Ha-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Mar 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TWkP7ZurZMY6uepDxsK6Ha-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol]]></media:description>                                                            <media:text><![CDATA[Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol]]></media:text>
                                <media:title type="plain"><![CDATA[Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TWkP7ZurZMY6uepDxsK6Ha-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Flashpoint warns of AI-driven “era of total convergence” in cybercrime </strong></li><li><strong>1,500% surge in illicit AI discussions, 3.3B credentials stolen in 2025</strong></li><li><strong>Ransomware shifting to insider-enabled, identity-focused attacks</strong></li></ul><p>Cybercrime has entered the “era of total convergence”, where everything from reconnaissance, phishing generation, to credential testing and infrastructure rotation is being done through agentic AI frameworks without any human control, exoerts have warned.</p><p>The <a href="https://flashpoint.io/blog/global-threat-intelligence-report-2026/" target="_blank" rel="nofollow">2026 Global Threat Intelligence Report</a> (GTIG) by security researchers Flashpoint noted this “high-velocity threat engine” lowers the barrier to entry and speeds up threats, forcing defenders to adapt or face the consequences.   </p><p>As per the report, there are four converging forces that are currently reshaping the global threat landscape: autonomous systems that can execute end-to-end attacks at machine speed, identities as primary exploit vectors, vulnerabilities being exploited within hours, rather than days, and ransomware shifting towards identity-driven and insider-enabled models. </p><h2 id="logging-in-instead-of-breaking-in">Logging in instead of breaking in</h2><p>Flashpoint bases these conclusions on proprietary data, having apparently identified a 1,500% rise in AI-related illicit discussions between November and December 2025, rising from roughly 360,000, to more than six million.</p><p>At the same time, the company observed 11.1 million devices infected with infostealers in 2025, stealing approximately 3.3 billion credentials and cloud tokens. </p><p>It says that hackers are no longer interested in “breaking in” as much as they’re interested in “logging in”. “The reality of identity data and the potential for its automation necessitates a shift in how organizations must view their attack surface,” the researchers said. “Infostealers have shown that it is no longer limited to corporate infrastructure; it now includes employee browsers, personal devices, SaaS platforms, and third-party access.”</p><p>The researchers also said the window between vulnerability disclosure and exploitation is “vanishing”, as they observe several high-impact vulnerabilities being mass-exploited “within hours of disclosure”. </p><p>Finally, <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> incidents rose by 53% in 2025, with RaaS groups responsible for more than 87% of attacks. But instead of relying solely on encryption payloads, they are now recruiting malicious insiders, abusing authorized access, and leveraging credential theft. </p><p>To stay safe, organizations should focus on making sure they patch their vulnerabilities as soon as possible, Flashpoint said in the report. They should also focus on monitoring for stolen credentials and compromised endpoints, strengthening identity security, and combining automated detection with human-led threat intelligence to identify emerging risks early.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'The total industrialization of cyber threats': Cloudflare report outlines how hackers are 'weaponizing the Internet' ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/the-total-industrialization-of-cyber-threats-cloudflare-report-outlines-how-hackers-are-weaponizing-the-internet</link>
                                                                            <description>
                            <![CDATA[ There is a "fundamental rewiring of the modern cyberattack" going on and AI is at the center. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">F93UQ7GUjF3BPBfxkFSki6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hc6oTvWTHfb3ETNovTaDxG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Mar 2026 17:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hc6oTvWTHfb3ETNovTaDxG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI writer]]></media:description>                                                            <media:text><![CDATA[AI writer]]></media:text>
                                <media:title type="plain"><![CDATA[AI writer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hc6oTvWTHfb3ETNovTaDxG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cloudflare warns GenAI is reshaping cyberattacks </strong></li><li><strong>Report highlights AI-driven supply chain and espionage threats</strong></li><li><strong>DDoS and social engineering form critical attack trio</strong></li></ul><p>Generative Artificial Intelligence (GenAI) is the driving force behind a “fundamental rewiring of the modern cyberattack”, experts have said, urging companies to up their protection immediately. </p><p>The inaugural 2026 Cloudflare Threat Report, based on data from 230 billion threats the company blocks on average each day, claims we’re witnessing a complete industrialization of cybercrime, and says it is being adopted by both profit-driven and state-sponsored actors. </p><p>In the paper, the company details the “first-ever AI-based attack” recorded, in which a threat actor used AI to identify the location of high-value data, compromising hundreds of corporate tenants. It was “one of the most impactful supply chain attacks seen,” Cloudflare said.</p><h2 id="ddos-and-social-engineering">DDoS and social engineering</h2><p>Nation-states are also going all-in on AI. North Korean groups are apparently using AI-generated deepfakes and fake IDs to bypass hiring filters, smuggling state-sponsored spies directly into Western companies. They’re not even using <a href="https://www.techradar.com/vpn/best-vpn" target="_blank">VPN</a>s to hide their location. Instead, they are using local “laptop farms”.</p><p>While AI has not just lowered the barrier to entry, but erased it entirely, Cloudflare doesn’t focus solely on the nascent technology. It also mentions <a href="https://www.techradar.com/news/best-ddos-protection" target="_blank">DDoS</a> and social engineering, forming an “unholy trinity” of the contemporary cybercriminal.</p><p>DDoS attacks, for example, have now surpassed human response capabilities. Large-scale botnets like Aisuru have evolved into nation-state level threats capable of taking down entire country’s networks, Cloudflare warns, saying that with record-breaking attacks reaching 31.4 Tbps, these high-speed strikes now “demand fully autonomous defenses”.</p><p>“Threat actors are constantly changing tactics, finding new vulnerabilities to exploit and ways to overwhelm their victims. To avoid being caught off guard, organizations must shift from a reactive posture to one fueled by real-time, actionable intelligence,” said Blake Darché, head of threat intelligence, Cloudforce One at Cloudflare. </p><p>“The message to defenders is simple: lead with intelligence or risk falling behind in a race where the stakes have never been higher.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are turning to easy, fast AI solutions to roll out attacks - so how can your business stay safe? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-are-turning-to-easy-fast-ai-solutions-to-roll-out-attacks-so-how-can-your-business-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Between speed, quality, and cost, hackers must sacrifice one, and it appears to be - quality. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2vNxeVDinPoxdcenyQzBGQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Mar 2026 15:07:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:description>                                                            <media:text><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cybercriminals leverage GenAI to accelerate attack creation </strong></li><li><strong>Campaigns prioritize speed and scale over sophistication</strong></li><li><strong>Report shows basic tactics still bypass defenses</strong></li></ul><p>Cybercriminals are “vibe-hacking” their way into enterprise environments, using Generative Artificial Intelligence (GenAI) to make launching attacks faster and easier, research has claimed, noting although the attacks are less sophisticated compared to non-AI ones, this is a tradeoff cybercriminals are apparently happy to take.</p><p>The latest Threat Insights Report from HP Wolf Security claims to have seen <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> being used in different ways. In one campaign, a fake invoice PDF contained a link that triggered a download from a compromised site, before redirecting the victim to a trusted platform.</p><p>In another one, the crooks were using off-the-shelf <a href="https://www.techradar.com/best/best-malware-removal">malware</a> components and optimizing them with custom lures and payloads. This allows them to “quickly build, customize, and scale campaigns with minimal effort”. </p><h2 id="piggyback-attacks">Piggyback attacks</h2><p>The researchers also observed a so-called “piggyback” attack, in which malware was hidden in fake Teams installers. </p><p>Victims would download a malicious installer bundle with a hidden Oyster Loader malware piggybacking on the Teams installation process. So, while the real app is being installed, the victims don’t notice the infection happening in the background. </p><p>“It’s the classic project management triangle - speed, quality and cost. You often sacrifice one of them. What we’re seeing is many attackers are optimizing for speed and cost, not quality,” said Alex Holland, Principal Threat Research, HP Security Lab. </p><p>“They are not using AI to raise the bar; they’re using it to move faster and reduce effort. The campaigns themselves are basic but the uncomfortable reality is they still work.”</p><p>Looking at the report, it would seem that quality isn’t the defining factor here. As per HP’s telemetry, at least 14% of malicious emails managed to bypass one or more email gateway scanners, suggesting that the “low quality, high quantity” approach does work. The most popular delivery type were executable files (37%), .ZIP archives (11%), and .DOCX files (10%).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korean job scammers target JavaScript and Python developers with fake interview tasks spreading malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/north-korean-job-scammers-target-javascript-and-python-developers-with-fake-interview-tasks-spreading-malware</link>
                                                                            <description>
                            <![CDATA[ Operation Dream Job is evolving once again, and now comes through malicious dependencies on bare-bones projects. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3MoqZ4T5MWqXnL8vyBAx84</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PcYLLwL2xvYvPfjEXYpZrD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Feb 2026 15:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PcYLLwL2xvYvPfjEXYpZrD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker silhouette working on a laptop with North Korean flag on the background]]></media:description>                                                            <media:text><![CDATA[Hacker silhouette working on a laptop with North Korean flag on the background]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker silhouette working on a laptop with North Korean flag on the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PcYLLwL2xvYvPfjEXYpZrD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Lazarus Group evolving Operation Dream Job campaign to target Web3 developers </strong></li><li><strong>New “Graphalgo” variant uses malicious dependencies in legitimate bare-bone projects on PyPI/npm</strong></li><li><strong>ReversingLabs found ~200 malicious packages spoofing libraries like graphlib, aiming to steal crypto</strong></li></ul><p>The notorious Lazarus gang is evolving its Operation Dream Job campaign to target even more software developers and steal even more crypto along the way.</p><p>Security researchers ReversingLabs claim to have seen changes to the campaign starting May 2025, dubbed ‘Graphalgo’, which sees Lazarus take a legitimate bare-bone project, and adds a malicious dependency which they use in the attack.</p><p>For those unfamiliar with Operation Dream Job, it is an ongoing campaign created by North Korean state-sponsored hackers. They create fake job ads on LinkedIn and other platforms and offer enticing jobs to software developers working primarily in the Web3 (blockchain) industry.</p><h2 id="codename-graphalgo">Codename Graphalgo</h2><p>During the “hiring process”, they ask the candidates to go through a few test assignments which always end up with the victims downloading and running malicious code. That code can be different, but the goal is always to empty their <a href="https://www.techradar.com/news/best-bitcoin-wallets" target="_blank">crypto wallets</a> - be it standalone apps, browser add-ons, or accounts on popular crypto exchanges.</p><p>"It is easy to create such job task repositories. Threat actors simply need to take a legitimate bare-bone project and fix it up with a malicious dependency and it is ready to be served to targets," the researchers said. Most of these projects are hosted on legitimate platforms such as PyPI or npm, making it more difficult for the victims to spot the attack. </p><p>So far, ReversingLabs found almost 200 malicious packages. </p><p>The refresh was dubbed Graphalgo because all of the malicious packages had the prefix “graph” in their name and often spoof regular libraries such as graphlib. In more recent times, “graph” was replaced with “big”, but the researchers are yet to find the recruiting part that goes with these packages.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/fake-job-recruiters-hide-malware-in-developer-coding-challenges/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Most SMBs aren't set up to survive a major cyberattack - here's what needs to be done ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/most-smbs-arent-set-up-to-survive-a-major-cyberattack-heres-what-needs-to-be-done</link>
                                                                            <description>
                            <![CDATA[ One-tenth of UK orgs probably wouldn't survive after a cyberattack, and most agree risks have increased over the past 12 months. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y4hgLFe37VFgbex59iqAmf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Jan 2026 11:14:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Most business leaders believe their employees would fall for a phishing attack</strong></li><li><strong>Workers commonly reuse work passwords for personal accounts</strong></li><li><strong>AI scams and deepfakes are increasingly concerning</strong></li></ul><p>New data from Vodafone Business has revealed more than 10% of UK organizations would probably not survive if they were hit with a cyberattack, and while this may sound like a fairly low promotion by itself, it's set against a backdrop of evolving attacks and poor cybersecurity practices.</p><p>Nearly two-thirds (63%) agree that their business's risk of cyberattacks has risen over the past year, and most leaders (71%) believe at least one of their workers would probably fall for a phishing attack.</p><p>However, even though we're in an era of rapidly evolving threats, the report indicates that some basic cybersecurity measures can still serve to protect companies.</p><h2 id="british-businesses-are-still-at-risk-of-cyberattacks">British businesses are still at risk of cyberattacks</h2><p>One such practice is the use of strong and unique passwords. The study found that staff reuse work passwords on up to 11 personal accounts as well, making a single breach far more devastating.</p><p>And as for the current state up and down the UK, not even half (45%) have ensured that all staff have been through basic cyber awareness training.</p><p>But change could be on the horizon, with 89% agreeing that high-profile attacks last year (like those on M&S and Jaguar Land Rover) made them more alert.</p><p>There's also an increasing awareness of AI scams and deepfakes, with 70% now more suspicious of video calls claiming to be from senior leaders.</p><p>"Many steps - such as avoiding password reuse and enhancing staff training - are relatively simple to implement," VodafoneThree Business Director Nick Gliddon wrote.</p><p>The UK Government is also launching a second Telecommunications Fraud Charter later this year, with the hope of boosting the UK's defense against sophisticated cybercrime.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Notorious Black Axe cybercrime gang disrupted in Europol raids ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/notorious-black-axe-cybercrime-gang-disrupted-in-europol-raids</link>
                                                                            <description>
                            <![CDATA[ In total, 34 Black Axe cybercrime gang members were arrested, including core 10 members. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">H5oaPACgVBHCUvFh9iF7u9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 12 Jan 2026 11:43:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Spanish police arrest 34 suspected Black Axe members in raids across Seville, Madrid, Malaga, and Barcelona</strong></li><li><strong>Black Axe, linked to the Neo-Black Movement of Africa, has ~30,000 members worldwide</strong></li><li><strong>Group engages in cyber-fraud, trafficking, armed robbery, and recruits money mules in impoverished areas</strong></li></ul><p>Spanish police have arrested 34 individuals suspected of running Black Axe, a malicious organization engaged in <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">cyber fraud</a> as part of a network of criminal activities.</p><p>A <a href="https://www.europol.europa.eu/media-press/newsroom/news/34-arrests-in-spain-during-action-against-black-axe-criminal-organisation" target="_blank" rel="nofollow">Europol press release</a> noted the Spanish National Police and the Bavarian State Criminal Police Office conducted raids in Seville, Madrid, Malaga, and Barcelona, arresting dozens of members of Black Axe. During the raid, they seized almost $140,000 in bank accounts, and $77,000 in cash. </p><p>Black Axe is apparently a large, highly structured, hierarchical group headquartered in Nigeria, with members scattered across dozens of countries, while their operations span the globe.</p><h2 id="recruiting-money-mules">Recruiting money mules</h2><p>The group scammed their way into “billions of euros”, Europol explained, saying that it engages in all sorts of criminal activity: cyber-enabled fraud, drug trafficking, human trafficking and prostitution, kidnapping, armed robbery and fraudulent spiritual practices. The majority of their operations seem to be small-scale but add up quickly.</p><p>The core group that was arrested was allegedly engaged in recruiting money mules in Spain - mostly in impoverished areas. While the arrests were carried out mostly by Spanish operatives, German law enforcement provided analytical support and intelligence and deployed two officers during the raid. </p><p>Europol says Black Axe is formally linked to the Neo-Black Movement of Africa and is a “highly structured, hierarchical group with a global presence.”</p><p>“It divides its territory into approximately 60 zones in Nigeria and 35 abroad, with about 200 members per zone. In total, the organization has roughly 30 000 registered members, and countless affiliated individuals such as money mules and facilitators,” it said. </p><p>“The group enforces strict codes of conduct, violent and ritualistic initiations, and spiritual practices.”</p><p>No names were shared, and at this time, we don’t know exactly which cyber campaigns Black Axe conducted.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US cybersecurity professionals plead guilty to Blackcat ransomware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/us-cybersecurity-professionals-plead-guilty-to-blackcat-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ Ryan Clifford Goldberg and Kevin Tyler Martin could end up in prison for years after extorting one, and trying to extort four more companies. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5pGYF2n4SAMfnTdZdJyxhP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 31 Dec 2025 11:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Two ex-cybersecurity professionals pleaded guilty to ALPHV ransomware extortion attempts</strong></li><li><strong>They extorted $1.2M from a medical device firm; other attempts failed</strong></li><li><strong>Facing federal charges with possible 20-year prison sentences; sentencing set for March 12, 2026</strong></li></ul><p>The two cybersecurity experts that were accused of affiliating with <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> operators have pleaded guilty to at least one successful extortion attempt, as well as a few unsuccessful ones.</p><p>In early November this year, news broke of three cybersecurity professionals being suspected of working as affiliates for the dreaded ALPHV (BlackCat) ransomware gang, deploying encryptors against multiple US organizations.</p><p>Back then, a US federal indictment filed in the Southern District of Florida claimed two defendants - Ryan Clifford Goldberg of Georgia, and Kevin Tyler Martin of Texas, together with a third co-conspirator, hacked into company networks, stole data, encrypted it with ALPHV ransomware, and demanded cryptocurrency ransoms.</p><p>The indictment did not describe the two as cybersecurity professionals. However, local media said Martin worked at DigitalMint as a ransomware threat negotiator, while Goldberg was a former Sygnia incident response manager.</p><p>Both of them are no longer working with these companies.</p><h2 id="sentencing-in-march">Sentencing in March</h2><p>Now, it seems the duo admitted hacking a medical device company back in 2023, and later extorting it for $1.2 million. </p><p>They also allegedly admitted to trying to extort a Maryland-based pharmaceutical company, a California doctor’s office for $5 million, a California engineering firm for $1 million, and a Virginia drone manufacturer for $300,000. These attempts were unsuccessful.</p><p>“These defendants used their sophisticated cybersecurity training and experience to commit ransomware attacks – the very type of crime that they should have been working to stop,” said Assistant Attorney General A. Tysen Duva of the DoJ’s Criminal Division.</p><p>Since all five companies were engaged in interstate commerce, the case falls under federal jurisdiction. The payments were allegedly laundered through multiple cryptocurrency wallets to hide their origins.</p><p>The three are facing serious prison time. They are being charged with “conspiracy to interfere with interstate commerce by extortion”, “interference with ecommerce by extortion”, and “intentional damage to a protected computer”. The first two carry prison sentences of up to 20 years, while the third one 10 years.</p><p>Sentencing is scheduled for March 12, 2026.</p><p><em>Via </em><a href="https://cybernews.com/cybercrime/us-cyber-pros-guilty-alphv-blackcat-ransomware-affiliates/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Privacy vs control: a “whack-a-mole game” with no clear winners ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/computing/cyber-security/privacy-vs-control-a-whack-a-mole-game-with-no-clear-winners</link>
                                                                            <description>
                            <![CDATA[ Are authorities going too far in their pursuit of safety? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Q7uNQgkTKeU47dBAaxGcX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h3eTL5LaGoRRmYHVc9RnXL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rob Dunne ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SpemWktMnbiQ2SSmQ9RYtb.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rob is VPN Editor for TechRadar. Coming from a background in phones and technology, Rob has long been putting himself, and his data, online. Finding out the easy, and hard, ways to stay secure online is something that has come along the way – not without being victim to a number of nasty data breaches that is.&lt;/p&gt;&lt;p&gt;Using his experiences and broader knowledge of the technology world, Rob strives to provide the latest ways to stay secure and private online. Whether that be simple steps such as two-factor authentication and password management, or more advanced options such as setting up VPNs, alternative online aliases and more.&lt;/p&gt;&lt;p&gt;In an ever-busy life outside of work, Rob is constantly engaging in tech across areas such as fitness and smart wearables to help him with his continuous work in the gym or on the tennis court, as well as keeping up to date on the latest in the gaming industry with the latest releases across PC and console a constant release from day to day life. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h3eTL5LaGoRRmYHVc9RnXL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[person using phone with locked screen with iced coffee and laptop in background]]></media:description>                                                            <media:text><![CDATA[person using phone with locked screen with iced coffee and laptop in background]]></media:text>
                                <media:title type="plain"><![CDATA[person using phone with locked screen with iced coffee and laptop in background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h3eTL5LaGoRRmYHVc9RnXL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>VPNs have gained significant attention in 2025, and not all of it has been positive. The technology's role in circumventing age verification measures and accessing streaming services for reduced prices has consistently landed them in hot water. </p><p>Major events, like the arrival of age verification in the UK, have trigged massive increases in VPN demand, with one provider seeing sing-ups rise over 1,000%. Meanwhile, streaming services such as Canal+ have launched legal action against VPN companies for enabling improper access to their services. </p><p>As VPNs become increasingly important for accessing day-to-day services, they sit at the center of a growing conflict between privacy and control. However, have the events of 2025 shown that it’s a battle authorities simply can’t win? I think so.</p><h2 id="the-subscription-problem">The subscription problem</h2><p>Take streaming. As providers frequently increase prices and tighten geo-restrictions, VPNs have evolved into important tools for securing cheaper deals and unlocking foreign content libraries.</p><p>VPNs allow you to connect to a server in your home country if you’re traveling , so you can retain access to the content you love. However, it works both ways and you can just as easily access content that you strictly shouldn't be able to. </p><p>This capability drew the attention of streaming giant Canal+ earlier this year. The streaming service launched a legal case against VPNs, requesting that they block access to 203 sites identified as hosting pirated football streams. </p><p>But, as multiple VPNs have pointed out, these requests are near-impossible to implement without compromising their primary purpose, privacy. </p><div><blockquote><p>I don't think the walls are closing in."</p><p>Himmat Bains</p></blockquote></div><p>At the time of the initial ruling, a NordVPN spokesperson told TechRadar that adhering to the request while maintaining NordVPN’s privacy obligations was impossible. Almost a year later, the sentiment remains the consensus across the wider industry. </p><p>When asked whether Norton VPN was in a similar predicament regarding such requests, Himmat Bains, the company's Senior Principal Product Manager, simply responded:</p><p>“The problem is, I don’t know how we would.”  </p><p>Legal challenges like the one put forward by Canal+ aren’t common, and broader attempts to restrict the use of VPNs are even less frequent in democratic regions. So what’ll change? </p><p>Whether they are enabling safe journalism in conflict zones, bypassing state censorship, or securing personal data against malicious actors, the primary function of these tools is legitimate. As Bains concludes, despite the noise of 2025:</p><p>“I don’t think the walls are closing in.”</p><h2 id="portable-piracy">Portable piracy</h2><p>Amazon’s Fire TV Sticks have faced intense scrutiny throughout the year. The growth of ‘dodgy Fire Sticks’ has played a key driver in the estimated billions of dollars lost to IPTV piracy every year. </p><p>In response, Amazon has rolled out new updates to stop pirated content altogether. </p><p>This included creating a blacklist of sites known to show illegal content, which the provider hoped would quash access to pirated content entirely. However, according to Miguel Fornes, a cybersecurity expert at Surfshark, the issue is nowhere near solved. </p><p>“It’s a kind of whack-a-mole game," Fornes explained. "But it’s unwhackable.”  </p><p>Once one pirate site is found and blacklisted, it’s simple enough for the host to simply create a new site and start again. So, there isn’t necessarily an end in sight by going about it this way.</p><div><blockquote><p>It's not the final solution."</p><p>Miguel Fornes</p></blockquote></div><p>“It’s not the final solution," Fornes argues, "because otherwise, you’ll block the whole internet.”</p><p>There are legitimate reasons to install a VPN on an amazing Fire TV Stick, such as wanting to encrypt your data or giving you access to home shows while away. However, this flexibility is a double-edged sword – the same ecosystem that benefits legitimate uses also facilitates illegal viewing.</p><p>The device's portability adds another layer of complexity. Because users can simply plug the stick into any screen, anywhere, enforcement based on static locations or residential IP addresses becomes significantly harder to maintain.</p><p>The Alliance for Creativity and Entertainment is arguably the biggest collective fighting against online piracy. It has partnered with Amazon for it’s Fire TV measures and has Canal+ as one of its figurehead members. </p><p>Despite this heavyweight backing and Amazon's recent software crackdowns, the industry has yet to find a silver bullet for the role VPNs play in facilitating illicit streaming.</p><h2 id="what-s-next">What's next?</h2><p>No solution is perfect.</p><p>Amazon's strategy relies on time-consuming collaboration to identify and blacklist individual pirate domains. Furthermore, the targets are constantly moving. Sites like those targeted by Canal+ can simply update their DNS records or switch Content Delivery Networks (CDNs) to resume operations within minutes. </p><p>Meanwhile, VPN users are protected by the technology's no-logs infrastructure and encryption, making it difficult for authorities to identify people using them to access geo-restricted content. </p><p>As Fornes put it, "what Amazon is doing is the right thing", but, from everything we've seen so far, the right thing isn't necessarily enough. </p><p>No matter how many pirated sites are shut down and by what means, access to VPNs will remain constant due to their many legitimate uses. While legal pressure on providers may increase, the technical limitations of enforcing broad blocking requests suggest that VPNs will remain a persistent thorn in the side of authorities attempting to regain control.</p><p>We test and review VPN services in the context of legal recreational uses. For example:1. Accessing a service from another country (subject to the terms and conditions of that service).2. Protecting your online security and strengthening your online privacy when abroad.We do not support or condone using a VPN service to break the law or conduct illegal activities. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Companies are facing more cyberattacks than ever before - and many just can't cope ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/companies-are-facing-more-cyberattacks-than-ever-before-and-many-just-cant-cope</link>
                                                                            <description>
                            <![CDATA[ A lack of talent, resources and budget are preventing companies from being able to handle cyberattacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ufu9tSuSyZZxaKfqtbUMtg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h3qR8UKMq6wXR6WHZfxfUe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Sep 2025 14:29:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h3qR8UKMq6wXR6WHZfxfUe-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Representational image of a hacker]]></media:description>                                                            <media:text><![CDATA[Representational image of a hacker]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h3qR8UKMq6wXR6WHZfxfUe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ISACA figures show cyberattacks are happening more frequently</strong></li><li><strong>Understaffing and limited budgets are to blame</strong></li><li><strong>Used correctly, AI can plug the gap</strong></li></ul><p>New ISACA data has claimed two in five (39%) European professionals are reporting more cyberattacks than last year, with attacks increasing in both scale and complexity.</p><p>Even though rising attack frequency and severity isn’t a surprise (countless other reports correlate with this one), only around a third (38%) feel confident their organization can respond effectively, suggesting poor preparation and response to trends.</p><p>Poor readiness is being influenced by understaffing (58%) and poor budgets (54%), but both factors were cited less than last year suggesting that steady progress is being made.</p><h2 id="many-orgs-aren-t-ready-to-respond-to-cyberattacks">Many orgs aren’t ready to respond to cyberattacks</h2><p>"Over the past year, the public has seen first-hand just how impactful cyberattacks can be, with high-profile breaches devastating businesses and dominating headlines,” ISACA Chief Global Strategy Officer Chris Dimitriadis explained.</p><p>ISACA says there’s much more at play within organizations than just poor response and readiness – other struggles are spreading resources more thinly in general. Two-thirds (68%) of workers say their jobs are more stressful than five years ago, with more than half (54%) concerned about unrealistic expectations or excessive workloads.</p><p>A fifth (22%) of organizations have taken no action on burnout, and around one in three (36%) workers also note a lack of necessary skills and training.</p><p>“While organisations are starting to acknowledge the problem and take steps to address long-standing issues in budgets and staffing, the pace of change is still far too slow,” Dimitriadis noted.</p><p>Looking ahead, all of these factors are impacting on talent acquisition and retention for half (52%) of companies, with entry-level roles taking three to six months to fill for nearly one in two businesses.</p><p>Although <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence</a> has proven to be beneficial across threat detection (29%), endpoint security (28%) and general task automation (27%) among cybersecurity professionals, further AI security legislation and upskilling are required to match rising attacks.</p><p>“By valuing hands-on training, professional credentials and transferable skills, organisations can strengthen their teams and ease the pressure on overstretched professionals,” Dimitriadis concluded.</p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li>Here’s our roundup of the <a href="https://www.techradar.com/news/best-endpoint-security-software">best endpoint protection software</a></li><li><a href="https://www.techradar.com/pro/security/many-workers-wouldnt-tell-their-bosses-if-theyd-been-hit-by-a-cyberattack">Many workers wouldn't tell their bosses if they'd been hit by a cyberattack</a></li><li>The <a href="https://www.techradar.com/best/best-ransomware-protection">best ransomware protection</a> could futureproof you against rising cases</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ $10 million bounty issued by US DOJ for ransomware kingpin responsible for $18 billion of damage ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/usd10-million-bounty-issued-by-us-doj-for-ransomware-kingpin</link>
                                                                            <description>
                            <![CDATA[ The police are looking for a Ukrainian national allegedly responsible for millions in ransomware damages. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3csqUdC5HG4WoQ7waxrEye</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iB5kmNLRjGPKtpki7ahSwH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Sep 2025 10:43:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iB5kmNLRjGPKtpki7ahSwH-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Volodymyr Tymoshchuk]]></media:description>                                                            <media:text><![CDATA[Volodymyr Tymoshchuk]]></media:text>
                                <media:title type="plain"><![CDATA[Volodymyr Tymoshchuk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iB5kmNLRjGPKtpki7ahSwH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US offers $10M for arrest of ransomware suspect Volodymyr Tymoshchuk.</strong></li><li><strong>His group caused $18B in damage, including Norsk Hydro’s $80M loss</strong></li><li><strong>Europol-led global probe led to arrests and mapped the gang’s structure</strong></li></ul><p>The US Department of Justice (DoJ) just placed a bounty on a cybercriminal suspected of a “series” of cyberattacks around the world.</p><p>The reward is $10 million and will be paid out to anyone who provides enough information to result in his arrest. </p><p>The suspect’s name is Volodymyr Tymoshchuk, a 28-year-old Ukrainian. He is believed to be the mastermind behind the deployment of LockerGoga <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, which infected “hundreds of companies”. According to the EU Most Wanted website, his group caused more than $18 billion in damage worldwide.</p><h2 id="previous-arrests">Previous arrests</h2><p>Europol said in its press release that Tymoshchuk and his group were also responsible for the 2019 ransomware attack against a “major Norwegian aluminium company”. In underground criminal circles, he is known as Deadforz, Boba, Farnetwork, Msfv, and Volotmsk. </p><p>The European law enforcement agency also said that the identification of the suspect came after a complex international investigation, which included operations in France, Germany, Norway, Switzerland, Ukraine, the United Kingdom, and the United States. Both Europol and Eurojust (European Union Agency for Criminal Justice Cooperation) participated, as well. </p><p>While the hunt for Tymoshchuk is on, a few alleged members of his crew have already been arrested in Ukraine. This, Europol further stresses, helped the police map out the structure of the group and identify key individuals, including malware developers, intrusion specialists, and money launderers.</p><p>In mid-March 2019 Norsk Hydro, one of the world’s largest aluminium producers based in Norway, fell victim to a highly disruptive LockerGoga attack that encrypted thousands of endpoints, including corporate and industrial systems. Numerous facilities were impacted, including those in Norway, the US, Brazil, Qatar, and others. Reports at the time said up to 22,000 computers across 170 sites were impacted. </p><p>The financial fallout was significant. Losses in the first quarter were estimated at 300–350 million NOK (between $35 and 41 million), with additional operational costs mounting up in the weeks and months that followed. </p><p>By mid-2019, Norsk Hydro itself estimated the total cost of the attack across all business areas to be around 800 million NOK ($80 million).</p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/news/half-of-industrial-pcs-hit-by-cyberattacks-last-year" target="_blank">Half of industrial PCs hit by cyberattacks last year</a></li><li>Take a look at our guide to the <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">best authenticator app</a></li><li>We've rounded up the <a href="https://www.techradar.com/best/password-manager" target="_blank">best password managers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>